Skip to main content

Year archive

CVEs published in 2021

Archive summary

20,149 CVEs published in 2021 — 2,558 Critical, 8,477 High, 8,471 Medium, 643 Low, 0 Unrated.

CVE-2020-26972

Published Jan 7, 2021

The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a referenc…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-26768

Published Jan 7, 2021

Formstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation of user supplied input in the upload-target.php and upload-c…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24903

Published Jan 7, 2021

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulner…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24902

Published Jan 7, 2021

Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability u…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24901

Published Jan 7, 2021

The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24900

Published Jan 7, 2021

The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26085

Published Jan 7, 2021

Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying ope…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2020-8281

Published Jan 6, 2021

A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8280

Published Jan 6, 2021

A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 19,951-19,975 of 20,149 CVEsPage 799 of 806