2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36830MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress...
CVE-2021-45843MEDIUM6.1glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request ...
CVE-2021-45789MEDIUM6.5An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on th...
CVE-2021-43403MEDIUM6.5An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to cho...
CVE-2021-42049MEDIUM6.5An issue was discovered in the Translate extension in MediaWiki through 1.36.2. Oversighters cannot undo revisions or ov...
CVE-2021-42048MEDIUM4.8An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code...
CVE-2021-42047MEDIUM5.4An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard featu...
CVE-2021-42046MEDIUM6.1An issue was discovered in the GlobalWatchlist extension in MediaWiki through 1.36.2. The rev-deleted-user and ntimes me...
CVE-2021-42045MEDIUM5.4An issue was discovered in SecurePoll in the Growth extension in MediaWiki through 1.36.2. Simple polls allow users to c...
CVE-2021-40695MEDIUM4.3It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
CVE-2021-40694MEDIUM4.9Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP...
CVE-2021-40693MEDIUM6.5An authentication bypass risk was identified in the external database authentication functionality, due to a type juggli...
CVE-2021-40692MEDIUM4.3Insufficient capability checks made it possible for teachers to download users outside of their courses.
CVE-2021-40691MEDIUM4.3A session hijack risk was identified in the Shibboleth authentication plugin.
CVE-2021-41434MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application tha...
CVE-2021-27862MEDIUM4.7Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length ...
CVE-2021-27861MEDIUM4.7Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length ...
CVE-2021-27854MEDIUM4.7Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/S...
CVE-2021-27853MEDIUM4.7Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLA...
CVE-2021-28052MEDIUM4.9A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorizati...
CVE-2021-41437MEDIUM6.5An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to cr...
CVE-2021-45035MEDIUM5.9Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could al...
CVE-2021-3782MEDIUM6.6An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. Th...
CVE-2021-27774MEDIUM5.4User input included in error response, which could be used in a phishing attack.
CVE-2021-39190MEDIUM5.3The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now