2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3332MEDIUM5.3WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
CVE-2021-27318MEDIUM6.1Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to in...
CVE-2021-27317MEDIUM6.1Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to in...
CVE-2021-21515MEDIUM5.4Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privil...
CVE-2021-22114MEDIUM5.3Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write...
CVE-2021-27225MEDIUM5.4In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have cod...
CVE-2021-3151MEDIUM5.4i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attac...
CVE-2021-25284MEDIUM4.4An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or ...
CVE-2021-26565MEDIUM5.9Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before...
CVE-2021-26563MEDIUM6.7Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 all...
CVE-2021-0406MEDIUM6.7In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2021-0405MEDIUM6.7In performance driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local e...
CVE-2021-0404MEDIUM4.4In mobile_log_d, there is a possible information disclosure due to improper input validation. This could lead to local i...
CVE-2021-0403MEDIUM4.4In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local infor...
CVE-2021-0402MEDIUM6.7In jpeg, there is a possible out of bounds write due to improper input validation. This could lead to local escalation o...
CVE-2021-0401MEDIUM6.4In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ...
CVE-2021-0367MEDIUM6.4In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ...
CVE-2021-0366MEDIUM6.4In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ...
CVE-2021-23345MEDIUM5.3All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via t...
CVE-2021-21274MEDIUM6.5Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-21273MEDIUM6.1Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-21298MEDIUM6.5Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vu...
CVE-2021-21297MEDIUM6.5Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains...
CVE-2021-3010MEDIUM5.4There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server...
CVE-2021-26903MEDIUM6.1LMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text'].

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now