2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36352 | MEDIUM | 5.4 | 0.7% | Aug 26, 2021 | Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability h... |
| CVE-2021-38559 | MEDIUM | 6.1 | 1.0% | Aug 26, 2021 | DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter. |
| CVE-2021-20815 | MEDIUM | 6.1 | 0.9% | Aug 26, 2021 | Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and earlier (Movabl... |
| CVE-2021-20814 | MEDIUM | 6.1 | 0.9% | Aug 26, 2021 | Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable T... |
| CVE-2021-20813 | MEDIUM | 6.1 | 0.9% | Aug 26, 2021 | Cross-site scripting vulnerability in Edit screen of Content Data of Movable Type (Movable Type 7 r.4903 and earlier (Mo... |
| CVE-2021-20812 | MEDIUM | 6.1 | 0.9% | Aug 26, 2021 | Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and ... |
| CVE-2021-20811 | MEDIUM | 6.1 | 0.9% | Aug 26, 2021 | Cross-site scripting vulnerability in List of Assets screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable ... |
| CVE-2021-20810 | MEDIUM | 6.1 | 0.9% | Aug 26, 2021 | Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Mova... |
| CVE-2021-20809 | MEDIUM | 6.1 | 0.9% | Aug 26, 2021 | Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Movable Type 7 r.... |
| CVE-2021-20808 | MEDIUM | 6.1 | 0.9% | Aug 26, 2021 | Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 S... |
| CVE-2021-28070 | MEDIUM | 4.3 | 0.4% | Aug 25, 2021 | Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete. |
| CVE-2021-1592 | MEDIUM | 4.3 | 1.0% | Aug 25, 2021 | A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker... |
| CVE-2021-1591 | MEDIUM | 5.3 | 1.0% | Aug 25, 2021 | A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthent... |
| CVE-2021-1590 | MEDIUM | 5.3 | 1.6% | Aug 25, 2021 | A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unau... |
| CVE-2021-1584 | MEDIUM | 6.7 | 0.4% | Aug 25, 2021 | A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow ... |
| CVE-2021-1583 | MEDIUM | 4.4 | 0.2% | Aug 25, 2021 | A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Ap... |
| CVE-2021-1582 | MEDIUM | 5.4 | 0.6% | Aug 25, 2021 | A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could all... |
| CVE-2021-3605 | MEDIUM | 5.5 | 1.0% | Aug 25, 2021 | There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a ... |
| CVE-2021-31989 | MEDIUM | 5.3 | 0.4% | Aug 25, 2021 | A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions ex... |
| CVE-2021-22256 | MEDIUM | 5.4 | 0.7% | Aug 25, 2021 | Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry... |
| CVE-2021-22250 | MEDIUM | 5.4 | 0.8% | Aug 25, 2021 | Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation ... |
| CVE-2021-22247 | MEDIUM | 4.3 | 0.8% | Aug 25, 2021 | Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD... |
| CVE-2021-22244 | MEDIUM | 6.5 | 1.0% | Aug 25, 2021 | Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a repo... |
| CVE-2021-22243 | MEDIUM | 4.3 | 0.5% | Aug 25, 2021 | Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL m... |
| CVE-2021-22242 | MEDIUM | 5.4 | 63.6% | Aug 25, 2021 | Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now