2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-26698MEDIUM6.1OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) w...
CVE-2021-26230MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke...
CVE-2021-26227MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke...
CVE-2021-34700MEDIUM5.5A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to re...
CVE-2021-1617MEDIUM6.5Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an auth...
CVE-2021-1614MEDIUM5.3A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allo...
CVE-2021-1599MEDIUM5.4A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authen...
CVE-2021-34431MEDIUM6.5In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CO...
CVE-2021-29149MEDIUM6.2A local bypass security restrictions vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Ser...
CVE-2021-29148MEDIUM6.1A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Serie...
CVE-2021-35521MEDIUM5.9A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows rem...
CVE-2021-35520MEDIUM6.2A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows ph...
CVE-2021-30049MEDIUM6.1SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.
CVE-2021-1096MEDIUM5.5NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) ha...
CVE-2021-1095MEDIUM5.5NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler...
CVE-2021-1094MEDIUM6.1NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler...
CVE-2021-1093MEDIUM5.5NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert...
CVE-2021-37220MEDIUM5.5MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximu...
CVE-2021-32775MEDIUM6.5Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to m...
CVE-2021-32745MEDIUM6.1Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online pri...
CVE-2021-23408MEDIUM4.3This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser...
CVE-2021-21407MEDIUM6.5Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation ...
CVE-2021-37159MEDIUM6.4hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking...
CVE-2021-2445MEDIUM5.7Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). Th...
CVE-2021-2444MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now