2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-44050MEDIUM6.5CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due ...
CVE-2021-44518MEDIUM6.8An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing...
CVE-2021-3944MEDIUM6.8bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-23261MEDIUM4.9Authenticated administrators may override the system configuration file and cause a denial of service.
CVE-2021-23260MEDIUM5.4Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and ...
CVE-2021-43682MEDIUM6.1thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseControll...
CVE-2021-43686MEDIUM6.1nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will ter...
CVE-2021-43683MEDIUM6.1pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will termina...
CVE-2021-43681MEDIUM6.1SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit...
CVE-2021-43791MEDIUM5.3Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected ver...
CVE-2021-43794MEDIUM5.3Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i....
CVE-2021-43793MEDIUM4.3Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users...
CVE-2021-43792MEDIUM4.3Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who us...
CVE-2021-29863MEDIUM4.3IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacke...
CVE-2021-29849MEDIUM6.1IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2021-29779MEDIUM5.9IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exc...
CVE-2021-43687MEDIUM6.1chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an atta...
CVE-2021-44479MEDIUM5.5NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of ...
CVE-2021-43689MEDIUM6.1manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controll...
CVE-2021-40154MEDIUM5.5NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration req...
CVE-2021-44279MEDIUM6.1Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.
CVE-2021-44277MEDIUM6.1Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.
CVE-2021-25967MEDIUM5.4In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile pictur...
CVE-2021-43690MEDIUM6.1YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will ter...
CVE-2021-3983MEDIUM6.1kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now