2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-34724MEDIUM6A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileg...
CVE-2021-34723MEDIUM6.7A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, loca...
CVE-2021-34712MEDIUM6.5A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem...
CVE-2021-34705MEDIUM5.3A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software c...
CVE-2021-34703MEDIUM6.5A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Softwa...
CVE-2021-34696MEDIUM5.8A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Ro...
CVE-2021-1625MEDIUM5.8A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remot...
CVE-2021-1616MEDIUM4.7A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Ci...
CVE-2021-1589MEDIUM6.5A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote a...
CVE-2021-1546MEDIUM5.5A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive inf...
CVE-2021-21992MEDIUM6.5The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with...
CVE-2021-34648MEDIUM4.3The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in...
CVE-2021-34647MEDIUM6.5The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions funct...
CVE-2021-37860MEDIUM6.1Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to ...
CVE-2021-39404MEDIUM4.8MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database.
CVE-2021-39339MEDIUM5.3The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file ...
CVE-2021-38153MEDIUM5.9Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks...
CVE-2021-41087MEDIUM6.5in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected v...
CVE-2021-41086MEDIUM5.4jsuites is an open source collection of common required javascript web components. In affected versions users are subjec...
CVE-2021-41084MEDIUM4.7http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or re...
CVE-2021-40868MEDIUM6.1In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
CVE-2021-39230MEDIUM6.5Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are re...
CVE-2021-23443MEDIUM6.1This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization w...
CVE-2021-29795MEDIUM6IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of...
CVE-2021-41525MEDIUM5.5An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNe...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now