2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21292 | MEDIUM | 6.3 | 0.4% | Feb 2, 2021 | Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path v... |
| CVE-2021-21291 | MEDIUM | 6.1 | 1.4% | Feb 2, 2021 | OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google... |
| CVE-2021-20199 | MEDIUM | 5.9 | 1.1% | Feb 2, 2021 | Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote ho... |
| CVE-2021-21285 | MEDIUM | 6.5 | 3.3% | Feb 2, 2021 | In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker i... |
| CVE-2021-21284 | MEDIUM | 6.8 | 1.1% | Feb 2, 2021 | In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access ... |
| CVE-2021-3281 | MEDIUM | 5.3 | 7.6% | Feb 2, 2021 | In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "... |
| CVE-2021-3340 | MEDIUM | 6.1 | 0.8% | Feb 1, 2021 | A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote att... |
| CVE-2021-3024 | MEDIUM | 5.3 | 1.4% | Feb 1, 2021 | HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid... |
| CVE-2021-21266 | MEDIUM | 5 | 1.1% | Feb 1, 2021 | openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.... |
| CVE-2021-3350 | MEDIUM | 6.1 | 0.8% | Feb 1, 2021 | deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter. |
| CVE-2021-21254 | MEDIUM | 6.5 | 1.8% | Jan 29, 2021 | CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ck... |
| CVE-2021-23328 | MEDIUM | 5.6 | 1.0% | Jan 29, 2021 | This affects all versions of package iniparserjs. This vulnerability relates when ini_parser.js is concentrating arrays.... |
| CVE-2021-25910 | MEDIUM | 6.5 | 0.5% | Jan 29, 2021 | Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacke... |
| CVE-2021-3298 | MEDIUM | 5.4 | 2.1% | Jan 29, 2021 | Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit ... |
| CVE-2021-26307 | MEDIUM | 5.5 | 0.3% | Jan 29, 2021 | An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the proces... |
| CVE-2021-26304 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter. |
| CVE-2021-26303 | MEDIUM | 6.1 | 0.8% | Jan 29, 2021 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field. |
| CVE-2021-20185 | MEDIUM | 5.3 | 1.4% | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit wh... |
| CVE-2021-25647 | MEDIUM | 5.4 | 0.7% | Jan 28, 2021 | Mobile application "Testes de Codigo" v11.3 and prior allows stored XSS by injecting a payload in the "feedback" message... |
| CVE-2021-20186 | MEDIUM | 5.4 | 0.8% | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, addit... |
| CVE-2021-20184 | MEDIUM | 4.3 | 0.7% | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade relate... |
| CVE-2021-20183 | MEDIUM | 5.4 | 0.8% | Jan 28, 2021 | It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficien... |
| CVE-2021-22875 | MEDIUM | 6.1 | 22.1% | Jan 28, 2021 | Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter. |
| CVE-2021-22874 | MEDIUM | 6.1 | 22.1% | Jan 28, 2021 | Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset`... |
| CVE-2021-20622 | MEDIUM | 6.1 | 1.0% | Jan 28, 2021 | Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now