2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-27203MEDIUM5.5In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitr...
CVE-2021-20071MEDIUM4.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via t...
CVE-2021-20070MEDIUM4.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via t...
CVE-2021-20069MEDIUM4.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via th...
CVE-2021-20068MEDIUM4.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via th...
CVE-2021-20067MEDIUM5.3Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authen...
CVE-2021-20066MEDIUM5.6JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious we...
CVE-2021-27237MEDIUM4.8The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/...
CVE-2021-21317MEDIUM5.3uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In u...
CVE-2021-23841MEDIUM5.9The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer...
CVE-2021-27235MEDIUM4.9An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, there is a f...
CVE-2021-27233MEDIUM4.9An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password inf...
CVE-2021-27231MEDIUM5.4Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to cr...
CVE-2021-25299MEDIUM6.1Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/na...
CVE-2021-23336MEDIUM5.9The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9...
CVE-2021-26929MEDIUM6.1An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor...
CVE-2021-27210MEDIUM6.5TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,...
CVE-2021-22984MEDIUM6.1On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x be...
CVE-2021-22983MEDIUM5.4On BIG-IP AFM version 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.5, authenticated users acce...
CVE-2021-22981MEDIUM4.8On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiat...
CVE-2021-22979MEDIUM6.1On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12...
CVE-2021-20410MEDIUM5.3IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an...
CVE-2021-20408MEDIUM5.5IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to...
CVE-2021-20406MEDIUM4.9IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allo...
CVE-2021-27205MEDIUM5.5Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leadin...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now