2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-32760MEDIUM6.3containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and ext...
CVE-2021-34618MEDIUM6.5A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in versi...
CVE-2021-34617MEDIUM6.1A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve...
CVE-2021-34821MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2. The WebUI has wrong HTTP ...
CVE-2021-36797MEDIUM6.8In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device....
CVE-2021-29780MEDIUM4.7IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should no...
CVE-2021-20507MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-35043MEDIUM6.1OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected)...
CVE-2021-34817MEDIUM6.1A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary ...
CVE-2021-32014MEDIUM5.5SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xl...
CVE-2021-32013MEDIUM5.5SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted ...
CVE-2021-32012MEDIUM5.5SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted ...
CVE-2021-3279MEDIUM6.1sz.chat version 4 allows injection of web scripts and HTML in the message box.
CVE-2021-35968MEDIUM4.3The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly....
CVE-2021-35967MEDIUM5.3The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attack...
CVE-2021-35966MEDIUM6.1The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing...
CVE-2021-24482MEDIUM4.8The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high ...
CVE-2021-24452MEDIUM6.1The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the...
CVE-2021-24447MEDIUM5.3The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() ...
CVE-2021-24436MEDIUM6.1The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulne...
CVE-2021-36772MEDIUM6.1Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
CVE-2021-36771MEDIUM6.1Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
CVE-2021-36769MEDIUM5.3A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop befo...
CVE-2021-3614MEDIUM6.8A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevat...
CVE-2021-3453MEDIUM4.6Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now