2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-23176MEDIUM6.5Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise...
CVE-2021-36436MEDIUM5.3An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered ...
CVE-2021-38364MEDIUM6.5An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of flow rules installed by intents. A remote att...
CVE-2021-3429MEDIUM5.5When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that passw...
CVE-2021-43819MEDIUM5.3Stargate-Bukkit is a mod for the minecraft video game which adds a portal focused environment. In affected versions Mine...
CVE-2021-41613MEDIUM4.3An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The write logic of Exception Effective ...
CVE-2021-34337MEDIUM6.3An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks t...
CVE-2021-30153MEDIUM4.3An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35...
CVE-2021-3684MEDIUM5.5A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets we...
CVE-2021-3844MEDIUM5.4Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on...
CVE-2021-36821MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Fo...
CVE-2021-4195MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software ...
CVE-2021-46876MEDIUM5.3An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determi...
CVE-2021-46875MEDIUM6.1An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can ...
CVE-2021-27788MEDIUM6.1HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability.  By tricking a user into clicking a crafted URL,...
CVE-2021-4333MEDIUM6.5The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13....
CVE-2021-4332MEDIUM6.5The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and includin...
CVE-2021-44197MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technolo...
CVE-2021-44196MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technolo...
CVE-2021-36403MEDIUM5.3In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidde...
CVE-2021-36402MEDIUM5.3In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration...
CVE-2021-20251MEDIUM5.9A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks bei...
CVE-2021-36713MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary co...
CVE-2021-36401MEDIUM4.8In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
CVE-2021-36400MEDIUM5.3In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now