2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42656 | MEDIUM | 5.4 | 0.7% | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. |
| CVE-2021-42659 | MEDIUM | 6.5 | 0.8% | May 24, 2022 | There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9... |
| CVE-2021-32958 | MEDIUM | 5.5 | 0.2% | May 23, 2022 | Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows... |
| CVE-2021-42233 | MEDIUM | 5.4 | 0.8% | May 23, 2022 | The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any use... |
| CVE-2021-41714 | MEDIUM | 6.5 | 0.6% | May 23, 2022 | In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user... |
| CVE-2021-41834 | MEDIUM | 6.5 | 0.5% | May 23, 2022 | JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality ca... |
| CVE-2021-36833 | MEDIUM | 4.8 | 0.5% | May 20, 2022 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <=... |
| CVE-2021-39043 | MEDIUM | 5.4 | 0.4% | May 20, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerabil... |
| CVE-2021-43729 | MEDIUM | 5.4 | 0.6% | May 20, 2022 | Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability... |
| CVE-2021-43728 | MEDIUM | 5.4 | 0.6% | May 20, 2022 | Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability... |
| CVE-2021-45730 | MEDIUM | 4.9 | 0.5% | May 19, 2022 | JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit... |
| CVE-2021-38944 | MEDIUM | 6.1 | 0.5% | May 18, 2022 | IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnera... |
| CVE-2021-42851 | MEDIUM | 5.3 | 0.5% | May 18, 2022 | A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to c... |
| CVE-2021-42849 | MEDIUM | 6.8 | 0.2% | May 18, 2022 | A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow ... |
| CVE-2021-42848 | MEDIUM | 5.3 | 0.7% | May 18, 2022 | An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an u... |
| CVE-2021-3956 | MEDIUM | 5.3 | 0.7% | May 18, 2022 | A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Contro... |
| CVE-2021-27548 | MEDIUM | 5.5 | 0.7% | May 18, 2022 | There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03. |
| CVE-2021-41946 | MEDIUM | 5.4 | 2.4% | May 18, 2022 | In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access... |
| CVE-2021-35249 | MEDIUM | 4.3 | 0.6% | May 17, 2022 | This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user dat... |
| CVE-2021-29726 | MEDIUM | 5.3 | 0.8% | May 17, 2022 | IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a cert... |
| CVE-2021-42644 | MEDIUM | 6.5 | 0.9% | May 17, 2022 | cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file informa... |
| CVE-2021-42943 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrar... |
| CVE-2021-33021 | MEDIUM | 6.1 | 0.7% | May 16, 2022 | xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisa... |
| CVE-2021-33001 | MEDIUM | 6.1 | 0.7% | May 16, 2022 | xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisv... |
| CVE-2021-27442 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now