2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27526 | MEDIUM | 4.8 | 0.8% | Mar 23, 2021 | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "... |
| CVE-2021-27310 | MEDIUM | 6.1 | 2.8% | Mar 23, 2021 | Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter. |
| CVE-2021-27309 | MEDIUM | 6.1 | 2.0% | Mar 23, 2021 | Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter. |
| CVE-2021-21370 | MEDIUM | 5.4 | 0.9% | Mar 23, 2021 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.1... |
| CVE-2021-21358 | MEDIUM | 5.4 | 0.9% | Mar 23, 2021 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been di... |
| CVE-2021-21340 | MEDIUM | 5.4 | 0.9% | Mar 23, 2021 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been di... |
| CVE-2021-21338 | MEDIUM | 6.1 | 1.1% | Mar 23, 2021 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25... |
| CVE-2021-25922 | MEDIUM | 6.1 | 0.8% | Mar 22, 2021 | In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being v... |
| CVE-2021-25921 | MEDIUM | 5.4 | 91.1% | Mar 22, 2021 | In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being ... |
| CVE-2021-25920 | MEDIUM | 6.5 | 1.1% | Mar 22, 2021 | In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads... |
| CVE-2021-25919 | MEDIUM | 4.8 | 69.9% | Mar 22, 2021 | In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being vali... |
| CVE-2021-25918 | MEDIUM | 4.8 | 0.6% | Mar 22, 2021 | In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being vali... |
| CVE-2021-25917 | MEDIUM | 4.8 | 0.6% | Mar 22, 2021 | In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being vali... |
| CVE-2021-22321 | MEDIUM | 5.3 | 0.7% | Mar 22, 2021 | There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special sc... |
| CVE-2021-22310 | MEDIUM | 4.4 | 0.2% | Mar 22, 2021 | There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific informati... |
| CVE-2021-28972 | MEDIUM | 6.7 | 0.9% | Mar 22, 2021 | In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolera... |
| CVE-2021-28971 | MEDIUM | 5.5 | 0.4% | Mar 22, 2021 | In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, users... |
| CVE-2021-28968 | MEDIUM | 5.4 | 0.5% | Mar 22, 2021 | An issue was discovered in PunBB before 1.4.6. An XSS vulnerability in the [email] BBcode tag allows (with authenticatio... |
| CVE-2021-28147 | MEDIUM | 6.5 | 1.6% | Mar 22, 2021 | The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrec... |
| CVE-2021-27308 | MEDIUM | 4.8 | 2.2% | Mar 22, 2021 | A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to in... |
| CVE-2021-28146 | MEDIUM | 6.5 | 1.4% | Mar 22, 2021 | The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instan... |
| CVE-2021-28964 | MEDIUM | 4.7 | 0.3% | Mar 22, 2021 | A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attack... |
| CVE-2021-21438 | MEDIUM | 4.3 | 0.6% | Mar 22, 2021 | Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ versio... |
| CVE-2021-21437 | MEDIUM | 4.3 | 0.7% | Mar 22, 2021 | Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects... |
| CVE-2021-28963 | MEDIUM | 5.3 | 1.3% | Mar 22, 2021 | Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled p... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now