2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-27526MEDIUM4.8A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "...
CVE-2021-27310MEDIUM6.1Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.
CVE-2021-27309MEDIUM6.1Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.
CVE-2021-21370MEDIUM5.4TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.1...
CVE-2021-21358MEDIUM5.4TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been di...
CVE-2021-21340MEDIUM5.4TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been di...
CVE-2021-21338MEDIUM6.1TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25...
CVE-2021-25922MEDIUM6.1In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being v...
CVE-2021-25921MEDIUM5.4In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being ...
CVE-2021-25920MEDIUM6.5In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads...
CVE-2021-25919MEDIUM4.8In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being vali...
CVE-2021-25918MEDIUM4.8In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being vali...
CVE-2021-25917MEDIUM4.8In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being vali...
CVE-2021-22321MEDIUM5.3There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special sc...
CVE-2021-22310MEDIUM4.4There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific informati...
CVE-2021-28972MEDIUM6.7In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolera...
CVE-2021-28971MEDIUM5.5In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, users...
CVE-2021-28968MEDIUM5.4An issue was discovered in PunBB before 1.4.6. An XSS vulnerability in the [email] BBcode tag allows (with authenticatio...
CVE-2021-28147MEDIUM6.5The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrec...
CVE-2021-27308MEDIUM4.8A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to in...
CVE-2021-28146MEDIUM6.5The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instan...
CVE-2021-28964MEDIUM4.7A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attack...
CVE-2021-21438MEDIUM4.3Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ versio...
CVE-2021-21437MEDIUM4.3Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects...
CVE-2021-28963MEDIUM5.3Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled p...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now