2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29208MEDIUM4.8A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380...
CVE-2021-33425MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 whi...
CVE-2021-29207MEDIUM4.8A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrate...
CVE-2021-29206MEDIUM4.8A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrate...
CVE-2021-29205MEDIUM4.8A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrate...
CVE-2021-29204MEDIUM4.8A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrate...
CVE-2021-29202MEDIUM6.7A local buffer overflow vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HP...
CVE-2021-29201MEDIUM4.8A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrate...
CVE-2021-27821MEDIUM6.1The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerabil...
CVE-2021-30187MEDIUM5.3CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
CVE-2021-33562MEDIUM4.8A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitra...
CVE-2021-33561MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary ...
CVE-2021-23387MEDIUM6.1The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the UR...
CVE-2021-30083MEDIUM6.1An issue was discovered in Mediat 1.4.1. There is a Reflected XSS vulnerability which allows remote attackers to inject ...
CVE-2021-30082MEDIUM6.1An issue was discovered in Gris CMS v0.1. There is a Persistent XSS vulnerability which allows remote attackers to injec...
CVE-2021-32624MEDIUM5.3Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly disco...
CVE-2021-3485MEDIUM6.6An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linu...
CVE-2021-20428MEDIUM5.3IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error...
CVE-2021-20386MEDIUM6.1IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2021-3559MEDIUM6.5A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with...
CVE-2021-21989MEDIUM6.5VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read...
CVE-2021-21988MEDIUM6.5VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read...
CVE-2021-21987MEDIUM6.5VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read...
CVE-2021-25938MEDIUM6.1In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validatio...
CVE-2021-24332MEDIUM4.8The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now