2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4108 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-43051 | MEDIUM | 6.8 | 0.8% | Dec 14, 2021 | The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire ... |
| CVE-2021-39183 | MEDIUM | 6.1 | 0.7% | Dec 14, 2021 | Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are exe... |
| CVE-2021-34425 | MEDIUM | 6.1 | 0.9% | Dec 14, 2021 | The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side re... |
| CVE-2021-43820 | MEDIUM | 5.9 | 1.0% | Dec 14, 2021 | Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize acces... |
| CVE-2021-44043 | MEDIUM | 5.4 | 0.5% | Dec 14, 2021 | An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload function... |
| CVE-2021-43807 | MEDIUM | 6.5 | 1.4% | Dec 14, 2021 | Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP ... |
| CVE-2021-40882 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the loca... |
| CVE-2021-44235 | MEDIUM | 6.7 | 0.3% | Dec 14, 2021 | Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752... |
| CVE-2021-42367 | MEDIUM | 5.4 | 0.5% | Dec 14, 2021 | The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several paramet... |
| CVE-2021-42066 | MEDIUM | 4.4 | 0.4% | Dec 14, 2021 | SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should o... |
| CVE-2021-42063 | MEDIUM | 6.1 | 22.3% | Dec 14, 2021 | A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage... |
| CVE-2021-42061 | MEDIUM | 5.4 | 0.5% | Dec 14, 2021 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-c... |
| CVE-2021-41836 | MEDIUM | 4.8 | 0.6% | Dec 14, 2021 | The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ... |
| CVE-2021-3836 | MEDIUM | 5.5 | 0.9% | Dec 14, 2021 | dbeaver is vulnerable to Improper Restriction of XML External Entity Reference |
| CVE-2021-39319 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg pa... |
| CVE-2021-39318 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found... |
| CVE-2021-39315 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the... |
| CVE-2021-39314 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter foun... |
| CVE-2021-39313 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in... |
| CVE-2021-39311 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found ... |
| CVE-2021-39310 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/re... |
| CVE-2021-39309 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parame... |
| CVE-2021-39308 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientre... |
| CVE-2021-38361 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now