2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-32951MEDIUM5.3WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unautho...
CVE-2021-41866MEDIUM5.4MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not...
CVE-2021-35499MEDIUM5.4The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scriptin...
CVE-2021-41188MEDIUM5.4Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This ...
CVE-2021-41185MEDIUM6.5Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with a...
CVE-2021-41184MEDIUM6.1jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option...
CVE-2021-41183MEDIUM6.1jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`...
CVE-2021-41182MEDIUM6.1jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` ...
CVE-2021-41175MEDIUM5.4Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistic...
CVE-2021-41173MEDIUM5.7Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node i...
CVE-2021-41172MEDIUM5.4AS_Redis is an AntSword plugin for Redis. The Redis Manage plugin for AntSword prior to version 0.5 is vulnerable to Sel...
CVE-2021-41157MEDIUM5.3FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2021-34596MEDIUM6.5A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCW...
CVE-2021-41308MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to...
CVE-2021-41304MEDIUM6.1Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or ...
CVE-2021-41179MEDIUM6.5Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and ...
CVE-2021-41178MEDIUM6.5Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file tr...
CVE-2021-39224MEDIUM5.3Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version ...
CVE-2021-39223MEDIUM5.3Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to version...
CVE-2021-39221MEDIUM5.4Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0....
CVE-2021-41176MEDIUM4.3Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pter...
CVE-2021-34860MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li...
CVE-2021-34855MEDIUM6.5This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt...
CVE-2021-21319MEDIUM5.4Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, ...
CVE-2021-24885MEDIUM6.1The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now