2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22246MEDIUM6.5A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abuse...
CVE-2021-22238MEDIUM5.4An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS ...
CVE-2021-21823HIGH7.5An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 1...
CVE-2021-34433HIGH7.5In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handsh...
CVE-2021-34228MEDIUM6.1Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows...
CVE-2021-34223MEDIUM6.1Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows atta...
CVE-2021-34220MEDIUM6.1Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows at...
CVE-2021-34218MEDIUM5.3Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /ad...
CVE-2021-34215MEDIUM6.1Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attac...
CVE-2021-34207MEDIUM6.1Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers...
CVE-2021-37598MEDIUM5.3WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
CVE-2021-37597CRITICAL9.8WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
CVE-2021-28490HIGH8.8In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.
CVE-2021-39302CRITICAL9.8MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
CVE-2021-39138MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can u...
CVE-2021-37698HIGH7.5Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat...
CVE-2021-34645HIGH8.8The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_s...
CVE-2021-31868MEDIUM5.4Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket...
CVE-2021-31338HIGH7.8A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to...
CVE-2021-29280MEDIUM6.4In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
CVE-2021-24038HIGH7.8Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle ...
CVE-2021-28002MEDIUM5.4A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which a...
CVE-2021-28001MEDIUM5.4A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remo...
CVE-2021-28000MEDIUM4.8A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project...
CVE-2021-27999MEDIUM4.9A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System P...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now