2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3964MEDIUM5.9elgg is vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2021-4015MEDIUM4.3firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3993MEDIUM6.5showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3992MEDIUM6.5kimai2 is vulnerable to Improper Access Control
CVE-2021-3990MEDIUM6.5showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2021-3989MEDIUM6.1showdoc is vulnerable to URL Redirection to Untrusted Site
CVE-2021-4018MEDIUM5.4snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-20862MEDIUM4.3Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v...
CVE-2021-20858MEDIUM5.4Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenti...
CVE-2021-20857MEDIUM5.4Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenti...
CVE-2021-20856MEDIUM5.4Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware ...
CVE-2021-20855MEDIUM5.4Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware ...
CVE-2021-20854MEDIUM6.8ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-ad...
CVE-2021-20853MEDIUM6.8ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-ad...
CVE-2021-20852MEDIUM6.8Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02...
CVE-2021-20847MEDIUM6.1Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, ...
CVE-2021-36329MEDIUM6.5Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malici...
CVE-2021-36327MEDIUM5.3Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unaut...
CVE-2021-36326MEDIUM6.5Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A...
CVE-2021-4026MEDIUM4.3bookstack is vulnerable to Improper Access Control
CVE-2021-42564MEDIUM5.4An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (wit...
CVE-2021-31787MEDIUM6.5The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous un...
CVE-2021-44230MEDIUM6.5PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 databa...
CVE-2021-43295MEDIUM6.1Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
CVE-2021-43294MEDIUM6.1Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now