2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-28674MEDIUM5.4The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node ...
CVE-2021-28095MEDIUM4.8OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash coll...
CVE-2021-28094MEDIUM6.5OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, ...
CVE-2021-28093MEDIUM6.5OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due ...
CVE-2021-20789MEDIUM6.1Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, G...
CVE-2021-20788MEDIUM4.3Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version...
CVE-2021-20787MEDIUM4.8Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5...
CVE-2021-20786MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version ...
CVE-2021-20785MEDIUM4.8Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5...
CVE-2021-20113MEDIUM5.3An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for ...
CVE-2021-20112MEDIUM5.4A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.ph...
CVE-2021-20111MEDIUM5.4A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php wit...
CVE-2021-25273MEDIUM4.8Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
CVE-2021-21546MEDIUM5.5Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vuln...
CVE-2021-20505MEDIUM4.4The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange ...
CVE-2021-23416MEDIUM6.1This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitiz...
CVE-2021-32001MEDIUM6.5K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the...
CVE-2021-23414MEDIUM6.1This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execu...
CVE-2021-32796MEDIUM5.3xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. x...
CVE-2021-32788MEDIUM4.3Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post cre...
CVE-2021-32748MEDIUM4.3Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Plat...
CVE-2021-20562MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-s...
CVE-2021-32795MEDIUM5.9ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In ...
CVE-2021-37393MEDIUM5.4In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can ...
CVE-2021-37392MEDIUM5.4In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now