2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34223 | MEDIUM | 6.1 | 0.7% | Aug 20, 2021 | Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows atta... |
| CVE-2021-34220 | MEDIUM | 6.1 | 0.7% | Aug 20, 2021 | Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows at... |
| CVE-2021-34218 | MEDIUM | 5.3 | 0.8% | Aug 20, 2021 | Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /ad... |
| CVE-2021-34215 | MEDIUM | 6.1 | 0.7% | Aug 20, 2021 | Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attac... |
| CVE-2021-34207 | MEDIUM | 6.1 | 0.7% | Aug 20, 2021 | Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers... |
| CVE-2021-37598 | MEDIUM | 5.3 | 2.4% | Aug 19, 2021 | WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character. |
| CVE-2021-39138 | MEDIUM | 6.5 | 1.0% | Aug 19, 2021 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can u... |
| CVE-2021-31868 | MEDIUM | 5.4 | 0.5% | Aug 19, 2021 | Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket... |
| CVE-2021-29280 | MEDIUM | 6.4 | 0.8% | Aug 19, 2021 | In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow |
| CVE-2021-28002 | MEDIUM | 5.4 | 1.1% | Aug 19, 2021 | A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which a... |
| CVE-2021-28001 | MEDIUM | 5.4 | 1.0% | Aug 19, 2021 | A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remo... |
| CVE-2021-28000 | MEDIUM | 4.8 | 0.9% | Aug 19, 2021 | A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project... |
| CVE-2021-27999 | MEDIUM | 4.9 | 0.8% | Aug 19, 2021 | A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System P... |
| CVE-2021-27822 | MEDIUM | 4.8 | 0.6% | Aug 19, 2021 | A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System ... |
| CVE-2021-32602 | MEDIUM | 6.1 | 0.6% | Aug 19, 2021 | An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below... |
| CVE-2021-34734 | MEDIUM | 6.5 | 0.4% | Aug 18, 2021 | A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series ... |
| CVE-2021-1561 | MEDIUM | 5.4 | 0.7% | Aug 18, 2021 | A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management... |
| CVE-2021-39286 | MEDIUM | 6.1 | 0.7% | Aug 18, 2021 | Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped. |
| CVE-2021-39283 | MEDIUM | 5.5 | 0.9% | Aug 18, 2021 | liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP a... |
| CVE-2021-23425 | MEDIUM | 5.3 | 1.9% | Aug 18, 2021 | All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string proc... |
| CVE-2021-32728 | MEDIUM | 6.5 | 0.9% | Aug 18, 2021 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nex... |
| CVE-2021-38710 | MEDIUM | 6.1 | 0.6% | Aug 18, 2021 | Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An a... |
| CVE-2021-0628 | MEDIUM | 6.7 | 0.1% | Aug 18, 2021 | In OMA DRM, there is a possible memory corruption due to improper input validation. This could lead to local escalation ... |
| CVE-2021-0627 | MEDIUM | 6.7 | 0.1% | Aug 18, 2021 | In OMA DRM, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of pri... |
| CVE-2021-0626 | MEDIUM | 6.7 | 0.1% | Aug 18, 2021 | In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now