2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-47737MEDIUM5.4CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in...
CVE-2021-47733MEDIUM6.1CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML...
CVE-2021-47732MEDIUM6.1CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows at...
CVE-2021-47722MEDIUM5.1Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to m...
CVE-2021-47716MEDIUM5.4Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject ma...
CVE-2021-47715MEDIUM6.9Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remo...
CVE-2021-47714MEDIUM5.5Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL i...
CVE-2021-47729MEDIUM5.4Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that a...
CVE-2021-47727MEDIUM5.3Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live vid...
CVE-2021-47724MEDIUM6.5STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary fi...
CVE-2021-47717MEDIUM6.9IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumera...
CVE-2021-47704MEDIUM6.5OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries ...
CVE-2021-47702MEDIUM4.3OpenBMCS 2.4 contains a CSRF vulnerability that allows attackers to perform actions with administrative privileges by ex...
CVE-2021-4472MEDIUM6.5The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' featur...
CVE-2021-47698MEDIUM5.4Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core U...
CVE-2021-47699MEDIUM5.4Nagios XI versions prior to 5.8.7 are vulnerable to cross-site scripting (XSS) via the Audit Log page’s Send to NLS form...
CVE-2021-47697MEDIUM5.4Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insuf...
CVE-2021-47696MEDIUM5.4Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID handling. Insufficient ...
CVE-2021-47695MEDIUM5.4Nagios XI versions prior to 5.8.0 are vulnerable to stored cross-site scripting (XSS) via the My Tools page. Insufficien...
CVE-2021-47694MEDIUM6.1The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site...
CVE-2021-47691MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site sc...
CVE-2021-47690MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site sc...
CVE-2021-47689MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais a cross-site scripting ...
CVE-2021-43768MEDIUM5.3In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via th...
CVE-2021-42193MEDIUM6.1nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the prod...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now