2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36703MEDIUM6.1The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scrip...
CVE-2021-36702MEDIUM6.1The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage ...
CVE-2021-36543MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6...
CVE-2021-36542MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0....
CVE-2021-35343MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows...
CVE-2021-33330MEDIUM4.3Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharin...
CVE-2021-33328MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3....
CVE-2021-33327MEDIUM4.3The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1...
CVE-2021-33326MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP ...
CVE-2021-33325MEDIUM4.9The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix p...
CVE-2021-33324MEDIUM4.3The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack...
CVE-2021-33320MEDIUM4.3The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, an...
CVE-2021-36654MEDIUM5.4CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while...
CVE-2021-32018MEDIUM6.5An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to...
CVE-2021-27942MEDIUM6.8Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB driv...
CVE-2021-22424MEDIUM5.5A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability t...
CVE-2021-22419MEDIUM5.5A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exp...
CVE-2021-22417MEDIUM5.5A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability ...
CVE-2021-21581MEDIUM6.1Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could poten...
CVE-2021-21580MEDIUM4.3Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing /...
CVE-2021-21579MEDIUM6.1Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker m...
CVE-2021-21578MEDIUM6.1Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker m...
CVE-2021-21577MEDIUM6.1Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker c...
CVE-2021-21576MEDIUM6.1Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker c...
CVE-2021-36157MEDIUM5.3An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now