2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-31693MEDIUM6.1The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and t...
CVE-2021-25059MEDIUM4.3The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to acces...
CVE-2021-35246MEDIUM5.3The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a ...
CVE-2021-37936MEDIUM5.4It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an ...
CVE-2021-31739MEDIUM6.1The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly e...
CVE-2021-22141MEDIUM6.1An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously cr...
CVE-2021-36905MEDIUM5.4Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3....
CVE-2021-31608MEDIUM4.3Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.
CVE-2021-33897MEDIUM5.5A buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to caus...
CVE-2021-4241MEDIUM5.3A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedI...
CVE-2021-4240MEDIUM5.3A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePassw...
CVE-2021-40272MEDIUM6.1OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).
CVE-2021-38828MEDIUM5.3Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.
CVE-2021-33164MEDIUM6.7Improper access control in BIOS firmware for some Intel(R) NUCs before version INWHL357.0046 may allow a privileged user...
CVE-2021-33159MEDIUM6.7Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15....
CVE-2021-26251MEDIUM6.5Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potent...
CVE-2021-0185MEDIUM6.7Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a ...
CVE-2021-40289MEDIUM6.1mm-wki v0.2.1 is vulnerable to Cross Site Scripting (XSS).
CVE-2021-26393MEDIUM5.5Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authentic...
CVE-2021-34577MEDIUM6.5In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded sh...
CVE-2021-40303MEDIUM5.4perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.
CVE-2021-42205MEDIUM4.7ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows loca...
CVE-2021-39473MEDIUM5.4Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and conta...
CVE-2021-39432MEDIUM6.5diplib v3.0.0 is vulnerable to Double Free.
CVE-2021-39077MEDIUM4.4IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now