2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21613 | MEDIUM | 6.1 | 0.9% | Jan 13, 2021 | Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (... |
| CVE-2021-21612 | MEDIUM | 5.5 | 0.3% | Jan 13, 2021 | Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file o... |
| CVE-2021-21611 | MEDIUM | 5.4 | 1.0% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New ... |
| CVE-2021-21610 | MEDIUM | 6.1 | 1.2% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted... |
| CVE-2021-21609 | MEDIUM | 5.3 | 1.3% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessi... |
| CVE-2021-21608 | MEDIUM | 5.4 | 1.0% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross... |
| CVE-2021-21607 | MEDIUM | 6.5 | 1.4% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering ... |
| CVE-2021-21606 | MEDIUM | 4.3 | 1.2% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when che... |
| CVE-2021-21605 | HIGH | 8 | 2.2% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names th... |
| CVE-2021-21604 | HIGH | 8 | 1.7% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objec... |
| CVE-2021-21603 | MEDIUM | 5.4 | 1.0% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cr... |
| CVE-2021-21602 | MEDIUM | 6.5 | 2.2% | Jan 13, 2021 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces ... |
| CVE-2021-20616 | HIGH | 7.8 | 0.3% | Jan 13, 2021 | Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an att... |
| CVE-2021-23936 | MEDIUM | 6.1 | 0.9% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via the subject of a task. |
| CVE-2021-23935 | MEDIUM | 6.1 | 1.1% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code. |
| CVE-2021-23934 | MEDIUM | 6.1 | 1.1% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code. |
| CVE-2021-23933 | MEDIUM | 6.1 | 1.1% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL. |
| CVE-2021-23932 | MEDIUM | 6.1 | 1.1% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename. |
| CVE-2021-23931 | MEDIUM | 6.1 | 1.1% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an inline binary file. |
| CVE-2021-23930 | MEDIUM | 6.1 | 1.1% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile. |
| CVE-2021-23929 | MEDIUM | 6.1 | 1.1% | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/... |
| CVE-2021-23928 | MEDIUM | 6.1 | 1.1% | Jan 12, 2021 | OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string. |
| CVE-2021-23927 | MEDIUM | 6.4 | 0.8% | Jan 12, 2021 | OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request. |
| CVE-2021-23125 | MEDIUM | 6.1 | 0.8% | Jan 12, 2021 | An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple co... |
| CVE-2021-23124 | MEDIUM | 6.1 | 81.2% | Jan 12, 2021 | An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute al... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now