2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41747MEDIUM6.1Cross-Site Scripting (XSS) vulnerability exists in Csdn APP 4.10.0, which can be exploited by attackers to obtain sensit...
CVE-2021-38465MEDIUM6.5The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consum...
CVE-2021-38455MEDIUM6.5The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will...
CVE-2021-38451MEDIUM5.7The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those funct...
CVE-2021-35230MEDIUM6.7As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker...
CVE-2021-31682MEDIUM6.1The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for re...
CVE-2021-31835MEDIUM4.8Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrator...
CVE-2021-31834MEDIUM5.4Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO admini...
CVE-2021-41169MEDIUM4.8Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subje...
CVE-2021-36869MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable para...
CVE-2021-27746MEDIUM5.4"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"
CVE-2021-41168MEDIUM6.5Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affec...
CVE-2021-39357MEDIUM4.8The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and...
CVE-2021-39356MEDIUM4.8The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation a...
CVE-2021-39354MEDIUM4.8The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end...
CVE-2021-39348MEDIUM4.8The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom...
CVE-2021-39328MEDIUM4.8The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $...
CVE-2021-42715MEDIUM5.5An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines ...
CVE-2021-35228MEDIUM4.7This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from header...
CVE-2021-35225MEDIUM6.4Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath S...
CVE-2021-42327MEDIUM6.7dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 ...
CVE-2021-29883MEDIUM4.3IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on...
CVE-2021-28496MEDIUM6.5On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the pass...
CVE-2021-28975MEDIUM6.1WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted serve...
CVE-2021-35512MEDIUM6.5An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now