2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-20355MEDIUM5.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information...
CVE-2021-39047MEDIUM6.1IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. T...
CVE-2021-29768MEDIUM6.5IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the de...
CVE-2021-30651MEDIUM4.9A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that th...
CVE-2021-41639MEDIUM5.5MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
CVE-2021-41636MEDIUM6.5MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and op...
CVE-2021-41634MEDIUM5.3A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
CVE-2021-46824MEDIUM5.4Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter ...
CVE-2021-41432MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaS...
CVE-2021-29055MEDIUM6.1Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname paramete...
CVE-2021-36761MEDIUM5.3The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
CVE-2021-39006MEDIUM5.3IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best ...
CVE-2021-41924MEDIUM6.1Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2021-25121MEDIUM6.5The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of lon...
CVE-2021-25104MEDIUM6.1The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is ac...
CVE-2021-25088MEDIUM4.8The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug...
CVE-2021-46823MEDIUM6.5python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions,...
CVE-2021-46822MEDIUM5.5The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a...
CVE-2021-45026MEDIUM6.1ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
CVE-2021-36609MEDIUM5.4Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.
CVE-2021-36608MEDIUM5.4Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.
CVE-2021-33295MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code du...
CVE-2021-36827MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3....
CVE-2021-41421MEDIUM4.8A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the Maia...
CVE-2021-41420MEDIUM5.4A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execut...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now