2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40127 | MEDIUM | 5.3 | 1.2% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Bus... |
| CVE-2021-40126 | MEDIUM | 4.3 | 0.8% | Nov 4, 2021 | A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an... |
| CVE-2021-40115 | MEDIUM | 6.1 | 0.8% | Nov 4, 2021 | A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site script... |
| CVE-2021-34784 | MEDIUM | 5.4 | 0.6% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable ... |
| CVE-2021-34774 | MEDIUM | 4.9 | 1.0% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an ... |
| CVE-2021-34773 | MEDIUM | 6.5 | 0.5% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie... |
| CVE-2021-34731 | MEDIUM | 4.8 | 0.6% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remo... |
| CVE-2021-34701 | MEDIUM | 4.3 | 1.5% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie... |
| CVE-2021-1500 | MEDIUM | 6.1 | 0.8% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote a... |
| CVE-2021-34594 | MEDIUM | 6.5 | 1.1% | Nov 4, 2021 | TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.... |
| CVE-2021-41562 | MEDIUM | 6.1 | 0.2% | Nov 3, 2021 | A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue ... |
| CVE-2021-43032 | MEDIUM | 4.8 | 0.9% | Nov 3, 2021 | In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertisi... |
| CVE-2021-38488 | MEDIUM | 4.8 | 12.3% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-38428 | MEDIUM | 4.8 | 11.4% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-38418 | MEDIUM | 5.9 | 0.5% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be position... |
| CVE-2021-38411 | MEDIUM | 4.8 | 0.6% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-38407 | MEDIUM | 4.8 | 0.6% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-38403 | MEDIUM | 4.8 | 0.6% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-22960 | MEDIUM | 6.5 | 2.3% | Nov 3, 2021 | The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. Th... |
| CVE-2021-43141 | MEDIUM | 6.1 | 1.4% | Nov 3, 2021 | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter i... |
| CVE-2021-41174 | MEDIUM | 6.1 | 84.6% | Nov 3, 2021 | Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to conv... |
| CVE-2021-41134 | MEDIUM | 5.4 | 0.7% | Nov 3, 2021 | nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (... |
| CVE-2021-23784 | MEDIUM | 6.1 | 1.2% | Nov 3, 2021 | This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is r... |
| CVE-2021-23472 | MEDIUM | 6.1 | 2.3% | Nov 3, 2021 | This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of i... |
| CVE-2021-40985 | MEDIUM | 5.5 | 0.9% | Nov 3, 2021 | A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BM... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now