2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-40127MEDIUM5.3A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Bus...
CVE-2021-40126MEDIUM4.3A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an...
CVE-2021-40115MEDIUM6.1A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site script...
CVE-2021-34784MEDIUM5.4A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable ...
CVE-2021-34774MEDIUM4.9A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an ...
CVE-2021-34773MEDIUM6.5A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...
CVE-2021-34731MEDIUM4.8A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remo...
CVE-2021-34701MEDIUM4.3A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...
CVE-2021-1500MEDIUM6.1A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote a...
CVE-2021-34594MEDIUM6.5TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2....
CVE-2021-41562MEDIUM6.1A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue ...
CVE-2021-43032MEDIUM4.8In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertisi...
CVE-2021-38488MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-38428MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-38418MEDIUM5.9Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be position...
CVE-2021-38411MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-38407MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-38403MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-22960MEDIUM6.5The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. Th...
CVE-2021-43141MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter i...
CVE-2021-41174MEDIUM6.1Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to conv...
CVE-2021-41134MEDIUM5.4nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (...
CVE-2021-23784MEDIUM6.1This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is r...
CVE-2021-23472MEDIUM6.1This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of i...
CVE-2021-40985MEDIUM5.5A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BM...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now