2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-32842MEDIUM5.3SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a che...
CVE-2021-29838MEDIUM5.9IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure ...
CVE-2021-44692MEDIUM5.3BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new u...
CVE-2021-43334MEDIUM5.4BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
CVE-2021-22570MEDIUM5.5Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unche...
CVE-2021-44120MEDIUM5.4SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the functio...
CVE-2021-44118MEDIUM5.4SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must brows...
CVE-2021-36346MEDIUM5.3Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker c...
CVE-2021-4145MEDIUM6.5A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` poin...
CVE-2021-45729MEDIUM5.4The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authe...
CVE-2021-40337MEDIUM5.4Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulner...
CVE-2021-46087MEDIUM5.4In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not ...
CVE-2021-46085MEDIUM6.5OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators be...
CVE-2021-46084MEDIUM5.4uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via "close registration information" input box.
CVE-2021-46083MEDIUM5.4uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code.
CVE-2021-46034MEDIUM6.1A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickn...
CVE-2021-34870MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG...
CVE-2021-45847MEDIUM5.5Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to ca...
CVE-2021-45846MEDIUM5.5A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF ...
CVE-2021-45343MEDIUM5.5In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the applicat...
CVE-2021-45340MEDIUM6.5In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows a...
CVE-2021-46481MEDIUM5.5Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.
CVE-2021-46480MEDIUM5.5Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability...
CVE-2021-46478MEDIUM5.5Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can...
CVE-2021-46477MEDIUM5.5Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerabil...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now