2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-37823MEDIUM4.9OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the backgroun...
CVE-2021-46853MEDIUM5.9Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent be...
CVE-2021-45448MEDIUM6.5Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a ser...
CVE-2021-36864MEDIUM5.4Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4...
CVE-2021-38728MEDIUM6.1SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
CVE-2021-36863MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3...
CVE-2021-36858MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
CVE-2021-37781MEDIUM5.4Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.
CVE-2021-35388MEDIUM5.4Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
CVE-2021-36206MEDIUM6.1All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to by...
CVE-2021-45476MEDIUM4.7Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnera...
CVE-2021-45475MEDIUM5.3Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosur...
CVE-2021-45925MEDIUM5.3Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. Th...
CVE-2021-44776MEDIUM5.3A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbit...
CVE-2021-44769MEDIUM6.5An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Deni...
CVE-2021-26732MEDIUM5.3A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitr...
CVE-2021-33231MEDIUM5.4Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote a...
CVE-2021-36201MEDIUM5.3Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versi...
CVE-2021-36915MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows upload...
CVE-2021-36899MEDIUM4.8Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Boos...
CVE-2021-35226MEDIUM6.5An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Informatio...
CVE-2021-25044MEDIUM6.1The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage pa...
CVE-2021-36865MEDIUM4.3Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPres...
CVE-2021-36855MEDIUM6.1Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at W...
CVE-2021-36839MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now