2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-34223MEDIUM6.1Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows atta...
CVE-2021-34220MEDIUM6.1Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows at...
CVE-2021-34218MEDIUM5.3Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /ad...
CVE-2021-34215MEDIUM6.1Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attac...
CVE-2021-34207MEDIUM6.1Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers...
CVE-2021-37598MEDIUM5.3WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
CVE-2021-39138MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can u...
CVE-2021-31868MEDIUM5.4Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket...
CVE-2021-29280MEDIUM6.4In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
CVE-2021-28002MEDIUM5.4A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which a...
CVE-2021-28001MEDIUM5.4A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remo...
CVE-2021-28000MEDIUM4.8A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project...
CVE-2021-27999MEDIUM4.9A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System P...
CVE-2021-27822MEDIUM4.8A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System ...
CVE-2021-32602MEDIUM6.1An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below...
CVE-2021-34734MEDIUM6.5A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series ...
CVE-2021-1561MEDIUM5.4A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management...
CVE-2021-39286MEDIUM6.1Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped.
CVE-2021-39283MEDIUM5.5liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP a...
CVE-2021-23425MEDIUM5.3All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string proc...
CVE-2021-32728MEDIUM6.5The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nex...
CVE-2021-38710MEDIUM6.1Static (Persistent) XSS Vulnerability exists in version 4.3.0 of Yclas when using the install/view/form.php script. An a...
CVE-2021-0628MEDIUM6.7In OMA DRM, there is a possible memory corruption due to improper input validation. This could lead to local escalation ...
CVE-2021-0627MEDIUM6.7In OMA DRM, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of pri...
CVE-2021-0626MEDIUM6.7In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now