2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-43808MEDIUM6.1Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-s...
CVE-2021-44148MEDIUM6.1GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an a...
CVE-2021-43810MEDIUM6.1Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vu...
CVE-2021-42567MEDIUM6.1Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
CVE-2021-36760MEDIUM6.1In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS a...
CVE-2021-34544MEDIUM6.5An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cl...
CVE-2021-37940MEDIUM6.8An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Se...
CVE-2021-37085MEDIUM5.9There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to ...
CVE-2021-37082MEDIUM5.9There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to m...
CVE-2021-37058MEDIUM5.3There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this...
CVE-2021-37056MEDIUM5.3There is an Improper permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability...
CVE-2021-37055MEDIUM5.3There is a Logic bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attem...
CVE-2021-44527MEDIUM6.5A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gain...
CVE-2021-40096MEDIUM5.4A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote a...
CVE-2021-40095MEDIUM4.9An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptib...
CVE-2021-40094MEDIUM5.4A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may a...
CVE-2021-40093MEDIUM5.4A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote a...
CVE-2021-40092MEDIUM5.4A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inj...
CVE-2021-4049MEDIUM6.5livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-29116MEDIUM6.1A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server feature services versions 10.8.1 and 10.9 (only)...
CVE-2021-29115MEDIUM5.3An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and be...
CVE-2021-29113MEDIUM4.7A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attack...
CVE-2021-43784MEDIUM5runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is ...
CVE-2021-43781MEDIUM4.3Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. ...
CVE-2021-35245MEDIUM6.8When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed o...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now