2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-40994MEDIUM6.3A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas...
CVE-2021-40721MEDIUM6.1Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an at...
CVE-2021-39864MEDIUM6.5Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-si...
CVE-2021-40990MEDIUM6.5A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ...
CVE-2021-3875MEDIUM5.5vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3874MEDIUM6.5bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-39349MEDIUM4.8The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation an...
CVE-2021-39345MEDIUM4.8The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitizat...
CVE-2021-39344MEDIUM4.8The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation...
CVE-2021-39338MEDIUM4.8The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation...
CVE-2021-39337MEDIUM4.8The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sa...
CVE-2021-39336MEDIUM4.8The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and s...
CVE-2021-39335MEDIUM4.8The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validat...
CVE-2021-39334MEDIUM4.8The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ...
CVE-2021-39332MEDIUM4.8The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ...
CVE-2021-38431MEDIUM4.3An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose proj...
CVE-2021-42336MEDIUM4.3The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remot...
CVE-2021-42335MEDIUM5.4Easytest bulletin board management function of online learning platform does not filter special characters. After obtain...
CVE-2021-42332MEDIUM4.3The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s priv...
CVE-2021-42331MEDIUM5.4The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’...
CVE-2021-42329MEDIUM5.4The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title p...
CVE-2021-36387MEDIUM5.4In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploita...
CVE-2021-32571MEDIUM4.9In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and p...
CVE-2021-42227MEDIUM6.1Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.htm...
CVE-2021-32569MEDIUM6.1In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now