2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37467 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected). |
| CVE-2021-37466 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected). |
| CVE-2021-37465 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected). |
| CVE-2021-37464 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored). |
| CVE-2021-37463 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored). |
| CVE-2021-37462 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected). |
| CVE-2021-37461 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected). |
| CVE-2021-37460 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected). |
| CVE-2021-37459 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored). |
| CVE-2021-37458 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored). |
| CVE-2021-37457 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored). |
| CVE-2021-37456 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored). |
| CVE-2021-37455 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored). |
| CVE-2021-37454 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored). |
| CVE-2021-37453 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored). |
| CVE-2021-37452 | MEDIUM | 5.5 | 0.3% | Jul 25, 2021 | NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the... |
| CVE-2021-37451 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected). |
| CVE-2021-37450 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected). |
| CVE-2021-37438 | — | — | — | Jul 25, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3663 | HIGH | 7.5 | 0.7% | Jul 25, 2021 | firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts |
| CVE-2021-23413 | MEDIUM | 5.3 | 3.3% | Jul 25, 2021 | This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g ... |
| CVE-2021-37436 | MEDIUM | 4.2 | 0.3% | Jul 24, 2021 | Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a facto... |
| CVE-2021-32783 | HIGH | 8.5 | 1.2% | Jul 23, 2021 | Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted Exter... |
| CVE-2021-32686 | MEDIUM | 5.9 | 2.1% | Jul 23, 2021 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2021-3169 | CRITICAL | 9.8 | 2.8% | Jul 23, 2021 | An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now