2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36703 | MEDIUM | 6.1 | 0.9% | Aug 3, 2021 | The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scrip... |
| CVE-2021-36702 | MEDIUM | 6.1 | 0.9% | Aug 3, 2021 | The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage ... |
| CVE-2021-36543 | MEDIUM | 4.3 | 0.6% | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6... |
| CVE-2021-36542 | MEDIUM | 4.3 | 0.5% | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.... |
| CVE-2021-35343 | MEDIUM | 4.3 | 0.5% | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows... |
| CVE-2021-33330 | MEDIUM | 4.3 | 1.1% | Aug 3, 2021 | Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharin... |
| CVE-2021-33328 | MEDIUM | 5.4 | 0.7% | Aug 3, 2021 | Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.... |
| CVE-2021-33327 | MEDIUM | 4.3 | 0.9% | Aug 3, 2021 | The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1... |
| CVE-2021-33326 | MEDIUM | 6.1 | 1.0% | Aug 3, 2021 | Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP ... |
| CVE-2021-33325 | MEDIUM | 4.9 | 0.6% | Aug 3, 2021 | The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix p... |
| CVE-2021-33324 | MEDIUM | 4.3 | 0.9% | Aug 3, 2021 | The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack... |
| CVE-2021-33320 | MEDIUM | 4.3 | 1.2% | Aug 3, 2021 | The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, an... |
| CVE-2021-36654 | MEDIUM | 5.4 | 1.9% | Aug 3, 2021 | CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while... |
| CVE-2021-32018 | MEDIUM | 6.5 | 1.2% | Aug 3, 2021 | An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to... |
| CVE-2021-27942 | MEDIUM | 6.8 | 0.4% | Aug 3, 2021 | Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB driv... |
| CVE-2021-22424 | MEDIUM | 5.5 | 0.1% | Aug 3, 2021 | A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability t... |
| CVE-2021-22419 | MEDIUM | 5.5 | 0.1% | Aug 3, 2021 | A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exp... |
| CVE-2021-22417 | MEDIUM | 5.5 | 0.1% | Aug 3, 2021 | A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability ... |
| CVE-2021-21581 | MEDIUM | 6.1 | 0.9% | Aug 3, 2021 | Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could poten... |
| CVE-2021-21580 | MEDIUM | 4.3 | 0.8% | Aug 3, 2021 | Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing /... |
| CVE-2021-21579 | MEDIUM | 6.1 | 0.9% | Aug 3, 2021 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker m... |
| CVE-2021-21578 | MEDIUM | 6.1 | 0.9% | Aug 3, 2021 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker m... |
| CVE-2021-21577 | MEDIUM | 6.1 | 0.9% | Aug 3, 2021 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker c... |
| CVE-2021-21576 | MEDIUM | 6.1 | 0.9% | Aug 3, 2021 | Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker c... |
| CVE-2021-36157 | MEDIUM | 5.3 | 1.4% | Aug 3, 2021 | An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now