2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44050 | MEDIUM | 6.5 | 0.9% | Dec 2, 2021 | CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due ... |
| CVE-2021-44518 | MEDIUM | 6.8 | 0.3% | Dec 2, 2021 | An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing... |
| CVE-2021-3944 | MEDIUM | 6.8 | 0.6% | Dec 2, 2021 | bookstack is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-23261 | MEDIUM | 4.9 | 0.6% | Dec 2, 2021 | Authenticated administrators may override the system configuration file and cause a denial of service. |
| CVE-2021-23260 | MEDIUM | 5.4 | 0.4% | Dec 2, 2021 | Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and ... |
| CVE-2021-43682 | MEDIUM | 6.1 | 0.6% | Dec 2, 2021 | thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseControll... |
| CVE-2021-43686 | MEDIUM | 6.1 | 0.6% | Dec 2, 2021 | nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will ter... |
| CVE-2021-43683 | MEDIUM | 6.1 | 0.6% | Dec 2, 2021 | pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will termina... |
| CVE-2021-43681 | MEDIUM | 6.1 | 0.6% | Dec 2, 2021 | SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit... |
| CVE-2021-43791 | MEDIUM | 5.3 | 0.6% | Dec 2, 2021 | Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected ver... |
| CVE-2021-43794 | MEDIUM | 5.3 | 1.0% | Dec 1, 2021 | Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.... |
| CVE-2021-43793 | MEDIUM | 4.3 | 0.8% | Dec 1, 2021 | Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users... |
| CVE-2021-43792 | MEDIUM | 4.3 | 0.8% | Dec 1, 2021 | Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who us... |
| CVE-2021-29863 | MEDIUM | 4.3 | 0.5% | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacke... |
| CVE-2021-29849 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2021-29779 | MEDIUM | 5.9 | 1.2% | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exc... |
| CVE-2021-43687 | MEDIUM | 6.1 | 1.4% | Dec 1, 2021 | chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an atta... |
| CVE-2021-44479 | MEDIUM | 5.5 | 0.3% | Dec 1, 2021 | NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of ... |
| CVE-2021-43689 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controll... |
| CVE-2021-40154 | MEDIUM | 5.5 | 0.7% | Dec 1, 2021 | NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration req... |
| CVE-2021-44279 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php. |
| CVE-2021-44277 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php. |
| CVE-2021-25967 | MEDIUM | 5.4 | 0.5% | Dec 1, 2021 | In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile pictur... |
| CVE-2021-43690 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will ter... |
| CVE-2021-3983 | MEDIUM | 6.1 | 0.8% | Dec 1, 2021 | kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now