2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3204MEDIUM6.5SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the ser...
CVE-2021-3339MEDIUM4.3ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the S...
CVE-2021-26746MEDIUM6.1Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
CVE-2021-27404MEDIUM6.1Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.
CVE-2021-27403MEDIUM6.1Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.
CVE-2021-26906MEDIUM5.9An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0;...
CVE-2021-3271MEDIUM4.8PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Descriptio...
CVE-2021-21318MEDIUM5.4Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast b...
CVE-2021-20446MEDIUM5.4IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2021-20445MEDIUM6.5IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of...
CVE-2021-20444MEDIUM6.1IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2021-27124MEDIUM6.5SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated ...
CVE-2021-27375MEDIUM5.3Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.
CVE-2021-1416MEDIUM4.3Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot...
CVE-2021-1412MEDIUM6.5Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot...
CVE-2021-1372MEDIUM5.5A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticate...
CVE-2021-1351MEDIUM6.1A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to co...
CVE-2021-26697MEDIUM5.3The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allow...
CVE-2021-26559MEDIUM6.5Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User...
CVE-2021-22853MEDIUM5.4The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access ...
CVE-2021-23339MEDIUM6.5This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allow...
CVE-2021-20653MEDIUM5.3Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 ...
CVE-2021-26933MEDIUM5.5An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are byp...
CVE-2021-26932MEDIUM5.5An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in...
CVE-2021-26931MEDIUM5.5An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consid...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now