2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-37436MEDIUM4.2Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a facto...
CVE-2021-32686MEDIUM5.9PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2021-25809MEDIUM5.3UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() f...
CVE-2021-25791MEDIUM5.4Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S...
CVE-2021-25790MEDIUM5.4Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing...
CVE-2021-3159MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0....
CVE-2021-25204MEDIUM5.4Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject ar...
CVE-2021-20333MEDIUM5.3Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log e...
CVE-2021-26799MEDIUM6.1Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject ar...
CVE-2021-32786MEDIUM6.1mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co...
CVE-2021-34268MEDIUM4.6An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial...
CVE-2021-34267MEDIUM4.6An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial ...
CVE-2021-34262MEDIUM6.8A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and...
CVE-2021-34261MEDIUM4.6An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service d...
CVE-2021-34260MEDIUM6.8A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1....
CVE-2021-34259MEDIUM6.8A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 an...
CVE-2021-3619MEDIUM4.8Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, ...
CVE-2021-31581MEDIUM4.4The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Co...
CVE-2021-27332MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke...
CVE-2021-26224MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject ar...
CVE-2021-25197MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to in...
CVE-2021-37403MEDIUM6.1OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) w...
CVE-2021-37402MEDIUM6.1OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the l...
CVE-2021-33478MEDIUM6.8The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proxim...
CVE-2021-26699MEDIUM5.4OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled b...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now