2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-32470MEDIUM6.1Craft CMS before 3.6.13 has an XSS vulnerability.
CVE-2021-27571MEDIUM5.3An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applicat...
CVE-2021-27570MEDIUM5.3An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the proc...
CVE-2021-27569MEDIUM5.3An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a runnin...
CVE-2021-29488MEDIUM5.3SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem....
CVE-2021-21419MEDIUM5.3Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending ...
CVE-2021-3502MEDIUM5.5A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing ...
CVE-2021-26123MEDIUM6.1LivingLogic XIST4C before 0.107.8 allows XSS via login.htm, login.wihtm, or login-form.htm.
CVE-2021-26122MEDIUM6.1LivingLogic XIST4C before 0.107.8 allows XSS via feedback.htm or feedback.wihtm.
CVE-2021-30173MEDIUM6.5Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inj...
CVE-2021-30172MEDIUM5.4Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which ...
CVE-2021-30171MEDIUM5.4Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can...
CVE-2021-30170MEDIUM5.4Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated a...
CVE-2021-1906MEDIUM5.5Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Aut...
CVE-2021-32093MEDIUM6.5The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to rea...
CVE-2021-32092MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the DocumentAction component of U.S. National Security Agency (NSA) Emissa...
CVE-2021-32091MEDIUM6.1A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6.
CVE-2021-32103MEDIUM4.8A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authentic...
CVE-2021-32100MEDIUM6.5A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.
CVE-2021-27941MEDIUM4.6Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile applic...
CVE-2021-31916MEDIUM6.7An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver m...
CVE-2021-3507MEDIUM6.1A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_t...
CVE-2021-32052MEDIUM6.1In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibi...
CVE-2021-31829MEDIUM5.5kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure o...
CVE-2021-28150MEDIUM5.5Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and oth...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now