2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45843MEDIUM6.1glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request ...
CVE-2021-45790CRITICAL9.8An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to ar...
CVE-2021-45789MEDIUM6.5An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on th...
CVE-2021-45788HIGH8.8Time-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter.
CVE-2021-43403MEDIUM6.5An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to cho...
CVE-2021-42049MEDIUM6.5An issue was discovered in the Translate extension in MediaWiki through 1.36.2. Oversighters cannot undo revisions or ov...
CVE-2021-42048MEDIUM4.8An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code...
CVE-2021-42047MEDIUM5.4An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard featu...
CVE-2021-42046MEDIUM6.1An issue was discovered in the GlobalWatchlist extension in MediaWiki through 1.36.2. The rev-deleted-user and ntimes me...
CVE-2021-42045MEDIUM5.4An issue was discovered in SecurePoll in the Growth extension in MediaWiki through 1.36.2. Simple polls allow users to c...
CVE-2021-40695MEDIUM4.3It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
CVE-2021-40694MEDIUM4.9Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP...
CVE-2021-40693MEDIUM6.5An authentication bypass risk was identified in the external database authentication functionality, due to a type juggli...
CVE-2021-40692MEDIUM4.3Insufficient capability checks made it possible for teachers to download users outside of their courses.
CVE-2021-40691MEDIUM4.3A session hijack risk was identified in the Shibboleth authentication plugin.
CVE-2021-41434MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application tha...
CVE-2021-43980LOW3.7The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwa...
CVE-2021-41433CRITICAL9.8SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application logi...
CVE-2021-27862MEDIUM4.7Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length ...
CVE-2021-27861MEDIUM4.7Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length ...
CVE-2021-27854MEDIUM4.7Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/S...
CVE-2021-27853MEDIUM4.7Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLA...
CVE-2021-28052MEDIUM4.9A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorizati...
CVE-2021-41437MEDIUM6.5An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to cr...
CVE-2021-24890HIGH8.8The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now