2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-42656MEDIUM5.4SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-42659MEDIUM6.5There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9...
CVE-2021-32958MEDIUM5.5Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows...
CVE-2021-42233MEDIUM5.4The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any use...
CVE-2021-41714MEDIUM6.5In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user...
CVE-2021-41834MEDIUM6.5JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality ca...
CVE-2021-36833MEDIUM4.8Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <=...
CVE-2021-39043MEDIUM5.4IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerabil...
CVE-2021-43729MEDIUM5.4Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability...
CVE-2021-43728MEDIUM5.4Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability...
CVE-2021-45730MEDIUM4.9JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit...
CVE-2021-38944MEDIUM6.1IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnera...
CVE-2021-42851MEDIUM5.3A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to c...
CVE-2021-42849MEDIUM6.8A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow ...
CVE-2021-42848MEDIUM5.3An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an u...
CVE-2021-3956MEDIUM5.3A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Contro...
CVE-2021-27548MEDIUM5.5There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
CVE-2021-41946MEDIUM5.4In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access...
CVE-2021-35249MEDIUM4.3This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user dat...
CVE-2021-29726MEDIUM5.3IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a cert...
CVE-2021-42644MEDIUM6.5cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file informa...
CVE-2021-42943MEDIUM5.4Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrar...
CVE-2021-33021MEDIUM6.1xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisa...
CVE-2021-33001MEDIUM6.1xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisv...
CVE-2021-27442MEDIUM6.1The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now