2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-32844MEDIUM5.5HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper...
CVE-2021-32843MEDIUM5.5HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper...
CVE-2021-32419MEDIUM5.3An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm...
CVE-2021-23980MEDIUM6.1A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags s...
CVE-2021-33104MEDIUM5.5Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potential...
CVE-2021-43074MEDIUM4.3An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and bel...
CVE-2021-40555MEDIUM5.4Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via descripti...
CVE-2021-33396MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other inf...
CVE-2021-37519MEDIUM5.5Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted au...
CVE-2021-37518MEDIUM6.1Universal Cross Site Scripting (UXSS) vulnerability in Vimium Extension 1.66 and earlier allows remote attackers to run ...
CVE-2021-37502MEDIUM5.4Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user nam...
CVE-2021-37379MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrar...
CVE-2021-37378MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote a...
CVE-2021-37377MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Brik firmware version 7.2.x and earlier allows remote attackers to r...
CVE-2021-37376MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows ...
CVE-2021-37375MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote ...
CVE-2021-37374MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary ...
CVE-2021-37373MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attack...
CVE-2021-37234MEDIUM6.5Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows re...
CVE-2021-36712MEDIUM5.4Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping functio...
CVE-2021-36545MEDIUM5.4Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyrigh...
CVE-2021-36538MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run ar...
CVE-2021-36535MEDIUM5.5Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js f...
CVE-2021-36489MEDIUM6.5Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA...
CVE-2021-36425MEDIUM5.4Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $fil...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now