2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36843MEDIUM4.8Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin ...
CVE-2021-25269MEDIUM4.4A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service p...
CVE-2021-44225MEDIUM5.4In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user ...
CVE-2021-41270MEDIUM6.5Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and consol...
CVE-2021-41267MEDIUM6.5Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set...
CVE-2021-43268MEDIUM6.5An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to readin...
CVE-2021-43777MEDIUM6.1Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google L...
CVE-2021-41192MEDIUM6.5Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without exp...
CVE-2021-32037MEDIUM6.5An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregati...
CVE-2021-20848MEDIUM6.1Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary scr...
CVE-2021-20844MEDIUM5.7Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17...
CVE-2021-20843MEDIUM5.4Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and ear...
CVE-2021-20842MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack ...
CVE-2021-20841MEDIUM6.5Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker...
CVE-2021-20840MEDIUM6.1Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 all...
CVE-2021-40369MEDIUM6.1A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce...
CVE-2021-43221MEDIUM4.2Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2021-43211MEDIUM5.5Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-42297MEDIUM5Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-38004MEDIUM4.3Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cro...
CVE-2021-38000MEDIUM6.1Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote...
CVE-2021-37999MEDIUM6.1Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject ...
CVE-2021-38980MEDIUM5.3IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a re...
CVE-2021-38875MEDIUM6.5IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.1 CD, and 9.2 CD is vulnerable to a denial of service attack caused by an error...
CVE-2021-36334MEDIUM6.8Dell EMC CloudLink 7.1 and all prior versions contain a CSV formula Injection Vulnerability. A remote high privileged at...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now