2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-32244MEDIUM5.4Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Des...
CVE-2021-34204MEDIUM6.8D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the devic...
CVE-2021-32659MEDIUM4.9Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In version...
CVE-2021-1571MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a...
CVE-2021-1570MEDIUM6.5Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could ...
CVE-2021-1569MEDIUM6.5Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could ...
CVE-2021-1568MEDIUM5.5A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to c...
CVE-2021-1567MEDIUM6.7A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authe...
CVE-2021-1543MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a...
CVE-2021-1524MEDIUM6.5A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of se...
CVE-2021-1395MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate...
CVE-2021-20567MEDIUM4.4IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or none...
CVE-2021-20488MEDIUM6.5IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users i...
CVE-2021-20483MEDIUM6.5IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted ...
CVE-2021-34801MEDIUM5.3Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agen...
CVE-2021-21668MEDIUM5.4Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS...
CVE-2021-21667MEDIUM5.4Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in ...
CVE-2021-31857MEDIUM5.9In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a brow...
CVE-2021-31159MEDIUM5.3Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag...
CVE-2021-27479MEDIUM5.4ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to ...
CVE-2021-34683MEDIUM5.3An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/...
CVE-2021-32033MEDIUM4.6Protectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in cert...
CVE-2021-28979MEDIUM6.5SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could ex...
CVE-2021-27487MEDIUM5.5ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could ...
CVE-2021-27481MEDIUM5.5ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange proce...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now