2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-4092MEDIUM4.3yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-43815MEDIUM4.3Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a di...
CVE-2021-4089MEDIUM4.3snipe-it is vulnerable to Improper Access Control
CVE-2021-31747MEDIUM4.8Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-mid...
CVE-2021-43813MEDIUM4.3Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains...
CVE-2021-38937MEDIUM6.5IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a s...
CVE-2021-36911MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), cou...
CVE-2021-3829MEDIUM6.1openwhyd is vulnerable to URL Redirection to Untrusted Site
CVE-2021-40834MEDIUM4.3A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a special...
CVE-2021-37187MEDIUM6.5An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file...
CVE-2021-4084MEDIUM6.1pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4082MEDIUM4.3pimcore is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4081MEDIUM6.1pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4033MEDIUM6.5kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-43797MEDIUM6.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2021-38931MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclos...
CVE-2021-38926MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2021-4038MEDIUM4.8Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote ...
CVE-2021-41697MEDIUM6.1A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description pa...
CVE-2021-41696MEDIUM6.5An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password r...
CVE-2021-20137MEDIUM6.1A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the...
CVE-2021-22565MEDIUM6.5An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable t...
CVE-2021-42759MEDIUM6.7A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows atta...
CVE-2021-36167MEDIUM5.3An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 an...
CVE-2021-43410MEDIUM5.3Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now