2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37436 | MEDIUM | 4.2 | 0.3% | Jul 24, 2021 | Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a facto... |
| CVE-2021-32686 | MEDIUM | 5.9 | 2.1% | Jul 23, 2021 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2021-25809 | MEDIUM | 5.3 | 0.9% | Jul 23, 2021 | UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() f... |
| CVE-2021-25791 | MEDIUM | 5.4 | 2.5% | Jul 23, 2021 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S... |
| CVE-2021-25790 | MEDIUM | 5.4 | 0.9% | Jul 23, 2021 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing... |
| CVE-2021-3159 | MEDIUM | 5.4 | 0.5% | Jul 23, 2021 | A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.... |
| CVE-2021-25204 | MEDIUM | 5.4 | 0.7% | Jul 23, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject ar... |
| CVE-2021-20333 | MEDIUM | 5.3 | 1.3% | Jul 23, 2021 | Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log e... |
| CVE-2021-26799 | MEDIUM | 6.1 | 1.0% | Jul 23, 2021 | Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject ar... |
| CVE-2021-32786 | MEDIUM | 6.1 | 2.4% | Jul 22, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-34268 | MEDIUM | 4.6 | 0.4% | Jul 22, 2021 | An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial... |
| CVE-2021-34267 | MEDIUM | 4.6 | 0.4% | Jul 22, 2021 | An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial ... |
| CVE-2021-34262 | MEDIUM | 6.8 | 0.5% | Jul 22, 2021 | A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and... |
| CVE-2021-34261 | MEDIUM | 4.6 | 0.4% | Jul 22, 2021 | An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service d... |
| CVE-2021-34260 | MEDIUM | 6.8 | 0.5% | Jul 22, 2021 | A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.... |
| CVE-2021-34259 | MEDIUM | 6.8 | 0.5% | Jul 22, 2021 | A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 an... |
| CVE-2021-3619 | MEDIUM | 4.8 | 0.6% | Jul 22, 2021 | Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, ... |
| CVE-2021-31581 | MEDIUM | 4.4 | 1.2% | Jul 22, 2021 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Co... |
| CVE-2021-27332 | MEDIUM | 6.1 | 0.9% | Jul 22, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke... |
| CVE-2021-26224 | MEDIUM | 6.1 | 0.8% | Jul 22, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject ar... |
| CVE-2021-25197 | MEDIUM | 6.1 | 0.8% | Jul 22, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to in... |
| CVE-2021-37403 | MEDIUM | 6.1 | 0.8% | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) w... |
| CVE-2021-37402 | MEDIUM | 6.1 | 0.8% | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the l... |
| CVE-2021-33478 | MEDIUM | 6.8 | 0.3% | Jul 22, 2021 | The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proxim... |
| CVE-2021-26699 | MEDIUM | 5.4 | 2.0% | Jul 22, 2021 | OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled b... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now