2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43808 | MEDIUM | 6.1 | 0.8% | Dec 8, 2021 | Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-s... |
| CVE-2021-44148 | MEDIUM | 6.1 | 0.6% | Dec 7, 2021 | GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an a... |
| CVE-2021-43810 | MEDIUM | 6.1 | 5.8% | Dec 7, 2021 | Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vu... |
| CVE-2021-42567 | MEDIUM | 6.1 | 8.1% | Dec 7, 2021 | Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. |
| CVE-2021-36760 | MEDIUM | 6.1 | 0.7% | Dec 7, 2021 | In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS a... |
| CVE-2021-34544 | MEDIUM | 6.5 | 1.0% | Dec 7, 2021 | An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cl... |
| CVE-2021-37940 | MEDIUM | 6.8 | 0.8% | Dec 7, 2021 | An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Se... |
| CVE-2021-37085 | MEDIUM | 5.9 | 0.5% | Dec 7, 2021 | There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to ... |
| CVE-2021-37082 | MEDIUM | 5.9 | 0.4% | Dec 7, 2021 | There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to m... |
| CVE-2021-37058 | MEDIUM | 5.3 | 0.5% | Dec 7, 2021 | There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this... |
| CVE-2021-37056 | MEDIUM | 5.3 | 0.5% | Dec 7, 2021 | There is an Improper permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability... |
| CVE-2021-37055 | MEDIUM | 5.3 | 0.6% | Dec 7, 2021 | There is a Logic bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attem... |
| CVE-2021-44527 | MEDIUM | 6.5 | 0.4% | Dec 7, 2021 | A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gain... |
| CVE-2021-40096 | MEDIUM | 5.4 | 0.7% | Dec 7, 2021 | A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote a... |
| CVE-2021-40095 | MEDIUM | 4.9 | 1.0% | Dec 7, 2021 | An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptib... |
| CVE-2021-40094 | MEDIUM | 5.4 | 0.5% | Dec 7, 2021 | A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may a... |
| CVE-2021-40093 | MEDIUM | 5.4 | 0.6% | Dec 7, 2021 | A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote a... |
| CVE-2021-40092 | MEDIUM | 5.4 | 0.6% | Dec 7, 2021 | A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inj... |
| CVE-2021-4049 | MEDIUM | 6.5 | 0.4% | Dec 7, 2021 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-29116 | MEDIUM | 6.1 | 0.8% | Dec 7, 2021 | A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only)... |
| CVE-2021-29115 | MEDIUM | 5.3 | 2.1% | Dec 7, 2021 | An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and be... |
| CVE-2021-29113 | MEDIUM | 4.7 | 0.8% | Dec 7, 2021 | A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attack... |
| CVE-2021-43784 | MEDIUM | 5 | 1.7% | Dec 6, 2021 | runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is ... |
| CVE-2021-43781 | MEDIUM | 4.3 | 0.7% | Dec 6, 2021 | Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. ... |
| CVE-2021-35245 | MEDIUM | 6.8 | 1.2% | Dec 6, 2021 | When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed o... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now