2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34355 | MEDIUM | 5.4 | 0.6% | Oct 1, 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, thi... |
| CVE-2021-34354 | MEDIUM | 5.4 | 0.6% | Oct 1, 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, ... |
| CVE-2021-41324 | MEDIUM | 6.5 | 2.1% | Sep 30, 2021 | Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enu... |
| CVE-2021-41101 | MEDIUM | 5.7 | 0.7% | Sep 30, 2021 | wire-server is an open-source back end for Wire, a secure collaboration platform. Before version 2.106.0, the CORS ` Acc... |
| CVE-2021-41325 | MEDIUM | 6.5 | 1.1% | Sep 30, 2021 | Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via ... |
| CVE-2021-41323 | MEDIUM | 6.5 | 2.0% | Sep 30, 2021 | Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal... |
| CVE-2021-35205 | MEDIUM | 5.4 | 0.4% | Sep 30, 2021 | NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector. |
| CVE-2021-35204 | MEDIUM | 5.4 | 0.5% | Sep 30, 2021 | NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Reflected Cross-Site Scripting (XSS) in the support endpoint. |
| CVE-2021-35203 | MEDIUM | 5.7 | 0.7% | Sep 30, 2021 | NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint. |
| CVE-2021-35202 | MEDIUM | 4.3 | 0.6% | Sep 30, 2021 | NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService. |
| CVE-2021-35201 | MEDIUM | 6.5 | 0.9% | Sep 30, 2021 | NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks. |
| CVE-2021-35200 | MEDIUM | 4.8 | 0.4% | Sep 30, 2021 | NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQue... |
| CVE-2021-35199 | MEDIUM | 5.4 | 0.5% | Sep 30, 2021 | NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile. |
| CVE-2021-35198 | MEDIUM | 5.4 | 0.5% | Sep 30, 2021 | NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module. |
| CVE-2021-20554 | MEDIUM | 6.1 | 0.6% | Sep 30, 2021 | IBM Sterling Order Management 9.4, 9.5, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2021-24017 | MEDIUM | 4.3 | 0.5% | Sep 30, 2021 | An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign a... |
| CVE-2021-24016 | MEDIUM | 6.3 | 0.5% | Sep 30, 2021 | An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and... |
| CVE-2021-25963 | MEDIUM | 6.1 | 0.9% | Sep 30, 2021 | In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of ... |
| CVE-2021-41826 | MEDIUM | 6.1 | 11.9% | Sep 30, 2021 | PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect. |
| CVE-2021-41821 | MEDIUM | 6.5 | 1.1% | Sep 29, 2021 | Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial o... |
| CVE-2021-41795 | MEDIUM | 6.5 | 0.9% | Sep 29, 2021 | The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization ... |
| CVE-2021-22947 | MEDIUM | 5.9 | 2.8% | Sep 29, 2021 | When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS s... |
| CVE-2021-41573 | MEDIUM | 6.5 | 0.8% | Sep 29, 2021 | Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates ... |
| CVE-2021-40716 | MEDIUM | 5.5 | 2.2% | Sep 29, 2021 | XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to di... |
| CVE-2021-39861 | MEDIUM | 5.5 | 2.5% | Sep 29, 2021 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now