2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37445 | MEDIUM | 6.5 | 1.4% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading... |
| CVE-2021-37442 | MEDIUM | 6.5 | 1.2% | Jul 25, 2021 | NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files. |
| CVE-2021-37440 | MEDIUM | 6.5 | 1.2% | Jul 25, 2021 | NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring. |
| CVE-2021-37439 | MEDIUM | 6.5 | 1.2% | Jul 25, 2021 | NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability. |
| CVE-2021-37470 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user... |
| CVE-2021-37469 | MEDIUM | 6.5 | 1.2% | Jul 25, 2021 | In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the ... |
| CVE-2021-37467 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected). |
| CVE-2021-37466 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected). |
| CVE-2021-37465 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected). |
| CVE-2021-37464 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored). |
| CVE-2021-37463 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored). |
| CVE-2021-37462 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected). |
| CVE-2021-37461 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected). |
| CVE-2021-37460 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected). |
| CVE-2021-37459 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored). |
| CVE-2021-37458 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored). |
| CVE-2021-37457 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored). |
| CVE-2021-37456 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored). |
| CVE-2021-37455 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored). |
| CVE-2021-37454 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored). |
| CVE-2021-37453 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored). |
| CVE-2021-37452 | MEDIUM | 5.5 | 0.3% | Jul 25, 2021 | NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the... |
| CVE-2021-37451 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected). |
| CVE-2021-37450 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected). |
| CVE-2021-23413 | MEDIUM | 5.3 | 3.3% | Jul 25, 2021 | This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now