2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36352MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability h...
CVE-2021-38559MEDIUM6.1DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
CVE-2021-20815MEDIUM6.1Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and earlier (Movabl...
CVE-2021-20814MEDIUM6.1Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable T...
CVE-2021-20813MEDIUM6.1Cross-site scripting vulnerability in Edit screen of Content Data of Movable Type (Movable Type 7 r.4903 and earlier (Mo...
CVE-2021-20812MEDIUM6.1Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and ...
CVE-2021-20811MEDIUM6.1Cross-site scripting vulnerability in List of Assets screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable ...
CVE-2021-20810MEDIUM6.1Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Mova...
CVE-2021-20809MEDIUM6.1Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Movable Type 7 r....
CVE-2021-20808MEDIUM6.1Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 S...
CVE-2021-28070MEDIUM4.3Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.
CVE-2021-1592MEDIUM4.3A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker...
CVE-2021-1591MEDIUM5.3A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthent...
CVE-2021-1590MEDIUM5.3A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unau...
CVE-2021-1584MEDIUM6.7A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow ...
CVE-2021-1583MEDIUM4.4A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Ap...
CVE-2021-1582MEDIUM5.4A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could all...
CVE-2021-3605MEDIUM5.5There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a ...
CVE-2021-31989MEDIUM5.3A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions ex...
CVE-2021-22256MEDIUM5.4Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry...
CVE-2021-22250MEDIUM5.4Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation ...
CVE-2021-22247MEDIUM4.3Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD...
CVE-2021-22244MEDIUM6.5Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a repo...
CVE-2021-22243MEDIUM4.3Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL m...
CVE-2021-22242MEDIUM5.4Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now