2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21613MEDIUM6.1Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (...
CVE-2021-21612MEDIUM5.5Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file o...
CVE-2021-21611MEDIUM5.4Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New ...
CVE-2021-21610MEDIUM6.1Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted...
CVE-2021-21609MEDIUM5.3Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessi...
CVE-2021-21608MEDIUM5.4Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross...
CVE-2021-21607MEDIUM6.5Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering ...
CVE-2021-21606MEDIUM4.3Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when che...
CVE-2021-21605HIGH8Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names th...
CVE-2021-21604HIGH8Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objec...
CVE-2021-21603MEDIUM5.4Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cr...
CVE-2021-21602MEDIUM6.5Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces ...
CVE-2021-20616HIGH7.8Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an att...
CVE-2021-23936MEDIUM6.1OX App Suite through 7.10.4 allows XSS via the subject of a task.
CVE-2021-23935MEDIUM6.1OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.
CVE-2021-23934MEDIUM6.1OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.
CVE-2021-23933MEDIUM6.1OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
CVE-2021-23932MEDIUM6.1OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.
CVE-2021-23931MEDIUM6.1OX App Suite through 7.10.4 allows XSS via an inline binary file.
CVE-2021-23930MEDIUM6.1OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.
CVE-2021-23929MEDIUM6.1OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/...
CVE-2021-23928MEDIUM6.1OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.
CVE-2021-23927MEDIUM6.4OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
CVE-2021-23125MEDIUM6.1An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple co...
CVE-2021-23124MEDIUM6.1An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute al...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now