2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23176 | MEDIUM | 6.5 | 0.8% | Apr 25, 2023 | Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise... |
| CVE-2021-36436 | MEDIUM | 5.3 | 0.5% | Apr 20, 2023 | An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered ... |
| CVE-2021-38364 | MEDIUM | 6.5 | 0.8% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of flow rules installed by intents. A remote att... |
| CVE-2021-3429 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that passw... |
| CVE-2021-43819 | MEDIUM | 5.3 | 0.5% | Apr 19, 2023 | Stargate-Bukkit is a mod for the minecraft video game which adds a portal focused environment. In affected versions Mine... |
| CVE-2021-41613 | MEDIUM | 4.3 | 0.4% | Apr 18, 2023 | An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The write logic of Exception Effective ... |
| CVE-2021-34337 | MEDIUM | 6.3 | 0.3% | Apr 15, 2023 | An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks t... |
| CVE-2021-30153 | MEDIUM | 4.3 | 0.8% | Apr 15, 2023 | An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35... |
| CVE-2021-3684 | MEDIUM | 5.5 | 0.2% | Mar 24, 2023 | A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets we... |
| CVE-2021-3844 | MEDIUM | 5.4 | 0.4% | Mar 24, 2023 | Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on... |
| CVE-2021-36821 | MEDIUM | 6.1 | 0.4% | Mar 16, 2023 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Fo... |
| CVE-2021-4195 | MEDIUM | 6.1 | 0.4% | Mar 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software ... |
| CVE-2021-46876 | MEDIUM | 5.3 | 0.5% | Mar 12, 2023 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determi... |
| CVE-2021-46875 | MEDIUM | 6.1 | 0.4% | Mar 12, 2023 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can ... |
| CVE-2021-27788 | MEDIUM | 6.1 | 0.6% | Mar 10, 2023 | HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability. By tricking a user into clicking a crafted URL,... |
| CVE-2021-4333 | MEDIUM | 6.5 | 0.4% | Mar 7, 2023 | The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.... |
| CVE-2021-4332 | MEDIUM | 6.5 | 0.8% | Mar 7, 2023 | The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and includin... |
| CVE-2021-44197 | MEDIUM | 6.1 | 0.4% | Mar 7, 2023 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technolo... |
| CVE-2021-44196 | MEDIUM | 6.1 | 0.4% | Mar 7, 2023 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technolo... |
| CVE-2021-36403 | MEDIUM | 5.3 | 0.5% | Mar 6, 2023 | In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidde... |
| CVE-2021-36402 | MEDIUM | 5.3 | 0.5% | Mar 6, 2023 | In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration... |
| CVE-2021-20251 | MEDIUM | 5.9 | 0.8% | Mar 6, 2023 | A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks bei... |
| CVE-2021-36713 | MEDIUM | 6.1 | 0.8% | Mar 6, 2023 | Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary co... |
| CVE-2021-36401 | MEDIUM | 4.8 | 0.5% | Mar 6, 2023 | In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk. |
| CVE-2021-36400 | MEDIUM | 5.3 | 0.5% | Mar 6, 2023 | In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now