2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25333LOW2.4Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance informati...
CVE-2021-25332LOW2.4Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts informat...
CVE-2021-25331LOW2.4Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance informati...
CVE-2021-24032MEDIUM4.7Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility...
CVE-2021-24031MEDIUM5.5In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file ...
CVE-2021-20351MEDIUM5.4IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2021-20350MEDIUM5.4IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2021-20340MEDIUM5.4IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2021-27217MEDIUM4.4An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not ...
CVE-2021-26029MEDIUM5.3An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite ...
CVE-2021-26028MEDIUM5.5An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files ...
CVE-2021-26027MEDIUM5.3An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the cat...
CVE-2021-23132HIGH7.5An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads
CVE-2021-23131HIGH7.5An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.
CVE-2021-23130MEDIUM6.1An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.
CVE-2021-23129MEDIUM6.1An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead t...
CVE-2021-23128CRITICAL9.1An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (...
CVE-2021-23127CRITICAL9.1An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to ...
CVE-2021-23126MEDIUM5.3An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of gen...
CVE-2021-22128MEDIUM4.3An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authe...
CVE-2021-23346MEDIUM5.3This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certa...
CVE-2021-23344CRITICAL9.8The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
CVE-2021-22189HIGH7.2Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the ...
CVE-2021-22183MEDIUM5.4An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS ...
CVE-2021-21331LOW3.3The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of sensitive informat...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now