2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3332 | MEDIUM | 5.3 | 1.8% | Mar 1, 2021 | WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password. |
| CVE-2021-27318 | MEDIUM | 6.1 | 1.5% | Mar 1, 2021 | Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to in... |
| CVE-2021-27317 | MEDIUM | 6.1 | 1.3% | Mar 1, 2021 | Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to in... |
| CVE-2021-21515 | MEDIUM | 5.4 | 0.8% | Mar 1, 2021 | Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privil... |
| CVE-2021-22114 | MEDIUM | 5.3 | 1.0% | Mar 1, 2021 | Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write... |
| CVE-2021-27225 | MEDIUM | 5.4 | 0.5% | Mar 1, 2021 | In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have cod... |
| CVE-2021-3151 | MEDIUM | 5.4 | 1.2% | Feb 27, 2021 | i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attac... |
| CVE-2021-25284 | MEDIUM | 4.4 | 0.5% | Feb 27, 2021 | An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or ... |
| CVE-2021-26565 | MEDIUM | 5.9 | 0.7% | Feb 26, 2021 | Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before... |
| CVE-2021-26563 | MEDIUM | 6.7 | 0.5% | Feb 26, 2021 | Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 all... |
| CVE-2021-0406 | MEDIUM | 6.7 | 0.1% | Feb 26, 2021 | In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation... |
| CVE-2021-0405 | MEDIUM | 6.7 | 0.1% | Feb 26, 2021 | In performance driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local e... |
| CVE-2021-0404 | MEDIUM | 4.4 | 0.1% | Feb 26, 2021 | In mobile_log_d, there is a possible information disclosure due to improper input validation. This could lead to local i... |
| CVE-2021-0403 | MEDIUM | 4.4 | 0.1% | Feb 26, 2021 | In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local infor... |
| CVE-2021-0402 | MEDIUM | 6.7 | 0.1% | Feb 26, 2021 | In jpeg, there is a possible out of bounds write due to improper input validation. This could lead to local escalation o... |
| CVE-2021-0401 | MEDIUM | 6.4 | 0.1% | Feb 26, 2021 | In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ... |
| CVE-2021-0367 | MEDIUM | 6.4 | 0.1% | Feb 26, 2021 | In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ... |
| CVE-2021-0366 | MEDIUM | 6.4 | 0.1% | Feb 26, 2021 | In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ... |
| CVE-2021-23345 | MEDIUM | 5.3 | 1.1% | Feb 26, 2021 | All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via t... |
| CVE-2021-21274 | MEDIUM | 6.5 | 2.2% | Feb 26, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-21273 | MEDIUM | 6.1 | 1.8% | Feb 26, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-21298 | MEDIUM | 6.5 | 1.2% | Feb 26, 2021 | Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vu... |
| CVE-2021-21297 | MEDIUM | 6.5 | 1.4% | Feb 26, 2021 | Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains... |
| CVE-2021-3010 | MEDIUM | 5.4 | 0.9% | Feb 26, 2021 | There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server... |
| CVE-2021-26903 | MEDIUM | 6.1 | 1.0% | Feb 26, 2021 | LMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text']. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now