2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28684 | MEDIUM | 4.3 | 0.9% | Jun 21, 2021 | The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead ... |
| CVE-2021-33572 | MEDIUM | 6.5 | 0.7% | Jun 21, 2021 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in ce... |
| CVE-2021-24368 | MEDIUM | 6.1 | 0.8% | Jun 20, 2021 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape... |
| CVE-2021-32696 | MEDIUM | 5.3 | 1.1% | Jun 18, 2021 | The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a... |
| CVE-2021-32956 | MEDIUM | 6.1 | 0.7% | Jun 18, 2021 | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a m... |
| CVE-2021-32954 | MEDIUM | 6.5 | 2.1% | Jun 18, 2021 | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker t... |
| CVE-2021-23846 | MEDIUM | 5.9 | 0.5% | Jun 18, 2021 | When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obta... |
| CVE-2021-21997 | MEDIUM | 5.5 | 0.5% | Jun 18, 2021 | VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A mal... |
| CVE-2021-34815 | MEDIUM | 4.8 | 0.8% | Jun 18, 2021 | CheckSec Canopy before 3.5.2 allows XSS attacks against the login page via the LOGIN_PAGE_DISCLAIMER parameter. |
| CVE-2021-26835 | MEDIUM | 6.1 | 1.3% | Jun 18, 2021 | No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform r... |
| CVE-2021-26834 | MEDIUM | 5.4 | 0.7% | Jun 18, 2021 | A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code executio... |
| CVE-2021-33577 | MEDIUM | 5.3 | 0.6% | Jun 18, 2021 | An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves... |
| CVE-2021-33347 | MEDIUM | 5.4 | 0.5% | Jun 18, 2021 | An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag managem... |
| CVE-2021-32536 | MEDIUM | 6.1 | 0.8% | Jun 18, 2021 | The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaSc... |
| CVE-2021-34811 | MEDIUM | 4.3 | 0.8% | Jun 18, 2021 | Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16... |
| CVE-2021-34808 | MEDIUM | 5.3 | 1.0% | Jun 18, 2021 | Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remo... |
| CVE-2021-34553 | MEDIUM | 4.3 | 3.7% | Jun 18, 2021 | Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files a... |
| CVE-2021-32694 | MEDIUM | 5.5 | 1.0% | Jun 17, 2021 | Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the s... |
| CVE-2021-32426 | MEDIUM | 6.1 | 0.8% | Jun 17, 2021 | In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "... |
| CVE-2021-33557 | MEDIUM | 6.1 | 1.8% | Jun 17, 2021 | An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the retu... |
| CVE-2021-32575 | MEDIUM | 6.5 | 0.5% | Jun 17, 2021 | HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged t... |
| CVE-2021-32681 | MEDIUM | 5.4 | 1.1% | Jun 17, 2021 | Wagtail is an open source content management system built on Django. A cross-site scripting vulnerability exists in vers... |
| CVE-2021-31818 | MEDIUM | 4.3 | 0.6% | Jun 17, 2021 | Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API bec... |
| CVE-2021-31521 | MEDIUM | 5.4 | 1.4% | Jun 17, 2021 | Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS... |
| CVE-2021-32245 | MEDIUM | 5.4 | 0.5% | Jun 16, 2021 | In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malic... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now