2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32951 | MEDIUM | 5.3 | 0.9% | Oct 27, 2021 | WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unautho... |
| CVE-2021-41866 | MEDIUM | 5.4 | 0.5% | Oct 26, 2021 | MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not... |
| CVE-2021-35499 | MEDIUM | 5.4 | 0.6% | Oct 26, 2021 | The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scriptin... |
| CVE-2021-41188 | MEDIUM | 5.4 | 0.7% | Oct 26, 2021 | Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This ... |
| CVE-2021-41185 | MEDIUM | 6.5 | 1.4% | Oct 26, 2021 | Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with a... |
| CVE-2021-41184 | MEDIUM | 6.1 | 42.8% | Oct 26, 2021 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option... |
| CVE-2021-41183 | MEDIUM | 6.1 | 7.9% | Oct 26, 2021 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`... |
| CVE-2021-41182 | MEDIUM | 6.1 | 37.8% | Oct 26, 2021 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` ... |
| CVE-2021-41175 | MEDIUM | 5.4 | 0.9% | Oct 26, 2021 | Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistic... |
| CVE-2021-41173 | MEDIUM | 5.7 | 1.2% | Oct 26, 2021 | Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node i... |
| CVE-2021-41172 | MEDIUM | 5.4 | 1.0% | Oct 26, 2021 | AS_Redis is an AntSword plugin for Redis. The Redis Manage plugin for AntSword prior to version 0.5 is vulnerable to Sel... |
| CVE-2021-41157 | MEDIUM | 5.3 | 1.7% | Oct 26, 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2021-34596 | MEDIUM | 6.5 | 0.8% | Oct 26, 2021 | A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCW... |
| CVE-2021-41308 | MEDIUM | 6.5 | 1.0% | Oct 26, 2021 | Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to... |
| CVE-2021-41304 | MEDIUM | 6.1 | 0.8% | Oct 26, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or ... |
| CVE-2021-41179 | MEDIUM | 6.5 | 1.2% | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and ... |
| CVE-2021-41178 | MEDIUM | 6.5 | 1.7% | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file tr... |
| CVE-2021-39224 | MEDIUM | 5.3 | 0.8% | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version ... |
| CVE-2021-39223 | MEDIUM | 5.3 | 1.0% | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to version... |
| CVE-2021-39221 | MEDIUM | 5.4 | 0.5% | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.... |
| CVE-2021-41176 | MEDIUM | 4.3 | 0.5% | Oct 25, 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pter... |
| CVE-2021-34860 | MEDIUM | 6.5 | 1.4% | Oct 25, 2021 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li... |
| CVE-2021-34855 | MEDIUM | 6.5 | 0.3% | Oct 25, 2021 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt... |
| CVE-2021-21319 | MEDIUM | 5.4 | 0.9% | Oct 25, 2021 | Galette is a membership management web application geared towards non profit organizations. In versions prior to 0.9.5, ... |
| CVE-2021-24885 | MEDIUM | 6.1 | 0.9% | Oct 25, 2021 | The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now