2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-4108MEDIUM6.1snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-43051MEDIUM6.8The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire ...
CVE-2021-39183MEDIUM6.1Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are exe...
CVE-2021-34425MEDIUM6.1The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side re...
CVE-2021-43820MEDIUM5.9Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize acces...
CVE-2021-44043MEDIUM5.4An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload function...
CVE-2021-43807MEDIUM6.5Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP ...
CVE-2021-40882MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the loca...
CVE-2021-44235MEDIUM6.7Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752...
CVE-2021-42367MEDIUM5.4The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several paramet...
CVE-2021-42066MEDIUM4.4SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should o...
CVE-2021-42063MEDIUM6.1A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage...
CVE-2021-42061MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-c...
CVE-2021-41836MEDIUM4.8The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ...
CVE-2021-3836MEDIUM5.5dbeaver is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2021-39319MEDIUM6.1The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg pa...
CVE-2021-39318MEDIUM6.1The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found...
CVE-2021-39315MEDIUM6.1The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the...
CVE-2021-39314MEDIUM6.1The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter foun...
CVE-2021-39313MEDIUM6.1The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in...
CVE-2021-39311MEDIUM6.1The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found ...
CVE-2021-39310MEDIUM6.1The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/re...
CVE-2021-39309MEDIUM6.1The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parame...
CVE-2021-39308MEDIUM6.1The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientre...
CVE-2021-38361MEDIUM6.1The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now