2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29010 | MEDIUM | 4.8 | 0.8% | Mar 25, 2021 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in th... |
| CVE-2021-29009 | MEDIUM | 4.8 | 0.8% | Mar 25, 2021 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in th... |
| CVE-2021-29008 | MEDIUM | 4.8 | 0.8% | Mar 25, 2021 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.p... |
| CVE-2021-22889 | MEDIUM | 6.1 | 36.3% | Mar 25, 2021 | Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.... |
| CVE-2021-22888 | MEDIUM | 6.1 | 19.8% | Mar 25, 2021 | Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-... |
| CVE-2021-3467 | MEDIUM | 5.5 | 0.6% | Mar 25, 2021 | A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF ... |
| CVE-2021-3446 | MEDIUM | 5.5 | 0.1% | Mar 25, 2021 | A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a ... |
| CVE-2021-3443 | MEDIUM | 5.5 | 0.8% | Mar 25, 2021 | A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the J... |
| CVE-2021-27195 | MEDIUM | 5.9 | 0.8% | Mar 25, 2021 | Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay netwo... |
| CVE-2021-26597 | MEDIUM | 6.5 | 1.4% | Mar 25, 2021 | An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Si... |
| CVE-2021-26596 | MEDIUM | 5.4 | 0.7% | Mar 25, 2021 | An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaS... |
| CVE-2021-25367 | MEDIUM | 5.4 | 0.6% | Mar 25, 2021 | Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without ... |
| CVE-2021-25354 | MEDIUM | 5.3 | 0.5% | Mar 25, 2021 | Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in ... |
| CVE-2021-3449 | MEDIUM | 5.9 | 63.5% | Mar 25, 2021 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv... |
| CVE-2021-1423 | MEDIUM | 4.4 | 0.2% | Mar 24, 2021 | A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated,... |
| CVE-2021-1418 | MEDIUM | 6.5 | 0.9% | Mar 24, 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms coul... |
| CVE-2021-1417 | MEDIUM | 6.5 | 1.0% | Mar 24, 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms coul... |
| CVE-2021-1381 | MEDIUM | 6.1 | 0.3% | Mar 24, 2021 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthe... |
| CVE-2021-1376 | MEDIUM | 6.7 | 0.2% | Mar 24, 2021 | Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catal... |
| CVE-2021-1375 | MEDIUM | 6.7 | 0.2% | Mar 24, 2021 | Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catal... |
| CVE-2021-1374 | MEDIUM | 4.8 | 0.6% | Mar 24, 2021 | A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software for the Catalyst 9000... |
| CVE-2021-1371 | MEDIUM | 6.6 | 0.3% | Mar 24, 2021 | A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local att... |
| CVE-2021-1356 | MEDIUM | 4.3 | 0.9% | Mar 24, 2021 | Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-... |
| CVE-2021-1352 | MEDIUM | 6.5 | 0.4% | Mar 24, 2021 | A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauth... |
| CVE-2021-1281 | MEDIUM | 6.7 | 0.3% | Mar 24, 2021 | A vulnerability in CLI management in Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now