2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28674 | MEDIUM | 5.4 | 0.9% | Jul 30, 2021 | The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node ... |
| CVE-2021-28095 | MEDIUM | 4.8 | 0.9% | Jul 30, 2021 | OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash coll... |
| CVE-2021-28094 | MEDIUM | 6.5 | 1.1% | Jul 30, 2021 | OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, ... |
| CVE-2021-28093 | MEDIUM | 6.5 | 1.1% | Jul 30, 2021 | OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due ... |
| CVE-2021-20789 | MEDIUM | 6.1 | 0.9% | Jul 30, 2021 | Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, G... |
| CVE-2021-20788 | MEDIUM | 4.3 | 0.9% | Jul 30, 2021 | Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version... |
| CVE-2021-20787 | MEDIUM | 4.8 | 0.6% | Jul 30, 2021 | Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5... |
| CVE-2021-20786 | MEDIUM | 4.3 | 0.4% | Jul 30, 2021 | Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version ... |
| CVE-2021-20785 | MEDIUM | 4.8 | 0.6% | Jul 30, 2021 | Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5... |
| CVE-2021-20113 | MEDIUM | 5.3 | 1.3% | Jul 30, 2021 | An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for ... |
| CVE-2021-20112 | MEDIUM | 5.4 | 0.6% | Jul 30, 2021 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.ph... |
| CVE-2021-20111 | MEDIUM | 5.4 | 0.6% | Jul 30, 2021 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php wit... |
| CVE-2021-25273 | MEDIUM | 4.8 | 0.8% | Jul 29, 2021 | Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706. |
| CVE-2021-21546 | MEDIUM | 5.5 | 0.2% | Jul 29, 2021 | Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vuln... |
| CVE-2021-20505 | MEDIUM | 4.4 | 0.5% | Jul 29, 2021 | The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange ... |
| CVE-2021-23416 | MEDIUM | 6.1 | 0.8% | Jul 28, 2021 | This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitiz... |
| CVE-2021-32001 | MEDIUM | 6.5 | 0.3% | Jul 28, 2021 | K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the... |
| CVE-2021-23414 | MEDIUM | 6.1 | 2.6% | Jul 28, 2021 | This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execu... |
| CVE-2021-32796 | MEDIUM | 5.3 | 1.3% | Jul 27, 2021 | xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. x... |
| CVE-2021-32788 | MEDIUM | 4.3 | 0.9% | Jul 27, 2021 | Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post cre... |
| CVE-2021-32748 | MEDIUM | 4.3 | 1.0% | Jul 27, 2021 | Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Plat... |
| CVE-2021-20562 | MEDIUM | 5.4 | 0.9% | Jul 27, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-s... |
| CVE-2021-32795 | MEDIUM | 5.9 | 1.7% | Jul 26, 2021 | ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In ... |
| CVE-2021-37393 | MEDIUM | 5.4 | 0.5% | Jul 26, 2021 | In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can ... |
| CVE-2021-37392 | MEDIUM | 5.4 | 0.5% | Jul 26, 2021 | In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now