2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-28684MEDIUM4.3The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead ...
CVE-2021-33572MEDIUM6.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in ce...
CVE-2021-24368MEDIUM6.1The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape...
CVE-2021-32696MEDIUM5.3The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a...
CVE-2021-32956MEDIUM6.1Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a m...
CVE-2021-32954MEDIUM6.5Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker t...
CVE-2021-23846MEDIUM5.9When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obta...
CVE-2021-21997MEDIUM5.5VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A mal...
CVE-2021-34815MEDIUM4.8CheckSec Canopy before 3.5.2 allows XSS attacks against the login page via the LOGIN_PAGE_DISCLAIMER parameter.
CVE-2021-26835MEDIUM6.1No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform r...
CVE-2021-26834MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code executio...
CVE-2021-33577MEDIUM5.3An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves...
CVE-2021-33347MEDIUM5.4An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag managem...
CVE-2021-32536MEDIUM6.1The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaSc...
CVE-2021-34811MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16...
CVE-2021-34808MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remo...
CVE-2021-34553MEDIUM4.3Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files a...
CVE-2021-32694MEDIUM5.5Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the s...
CVE-2021-32426MEDIUM6.1In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "...
CVE-2021-33557MEDIUM6.1An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the retu...
CVE-2021-32575MEDIUM6.5HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged t...
CVE-2021-32681MEDIUM5.4Wagtail is an open source content management system built on Django. A cross-site scripting vulnerability exists in vers...
CVE-2021-31818MEDIUM4.3Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API bec...
CVE-2021-31521MEDIUM5.4Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS...
CVE-2021-32245MEDIUM5.4In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malic...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now