2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21292MEDIUM6.3Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path v...
CVE-2021-21291MEDIUM6.1OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google...
CVE-2021-20199MEDIUM5.9Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote ho...
CVE-2021-21285MEDIUM6.5In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker i...
CVE-2021-21284MEDIUM6.8In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access ...
CVE-2021-3281MEDIUM5.3In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "...
CVE-2021-3340MEDIUM6.1A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote att...
CVE-2021-3024MEDIUM5.3HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid...
CVE-2021-21266MEDIUM5openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2....
CVE-2021-3350MEDIUM6.1deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter.
CVE-2021-21254MEDIUM6.5CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ck...
CVE-2021-23328MEDIUM5.6This affects all versions of package iniparserjs. This vulnerability relates when ini_parser.js is concentrating arrays....
CVE-2021-25910MEDIUM6.5Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacke...
CVE-2021-3298MEDIUM5.4Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit ...
CVE-2021-26307MEDIUM5.5An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the proces...
CVE-2021-26304MEDIUM5.4PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.
CVE-2021-26303MEDIUM6.1PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.
CVE-2021-20185MEDIUM5.3It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit wh...
CVE-2021-25647MEDIUM5.4Mobile application "Testes de Codigo" v11.3 and prior allows stored XSS by injecting a payload in the "feedback" message...
CVE-2021-20186MEDIUM5.4It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, addit...
CVE-2021-20184MEDIUM4.3It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade relate...
CVE-2021-20183MEDIUM5.4It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficien...
CVE-2021-22875MEDIUM6.1Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.
CVE-2021-22874MEDIUM6.1Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset`...
CVE-2021-20622MEDIUM6.1Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now