2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41810MEDIUM4.8Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Ad...
CVE-2021-36844MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on W...
CVE-2021-29859MEDIUM6.8IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0...
CVE-2021-25102MEDIUM4.7The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect...
CVE-2021-25086MEDIUM6.1The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting ...
CVE-2021-4200MEDIUM5.4A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restr...
CVE-2021-31674MEDIUM6.1Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacke...
CVE-2021-31673MEDIUM6.1A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo...
CVE-2021-41994MEDIUM4.8A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to a...
CVE-2021-41993MEDIUM4.8A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading ...
CVE-2021-41992MEDIUM5.6A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading...
CVE-2021-3982MEDIUM5.5Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with...
CVE-2021-41948MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List ...
CVE-2021-38952MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2021-43932MEDIUM6.1Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed up...
CVE-2021-43930MEDIUM4.9Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabli...
CVE-2021-38939MEDIUM5.3IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user wi...
CVE-2021-38874MEDIUM4.3IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some sit...
CVE-2021-34590MEDIUM5.4In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker coul...
CVE-2021-34587MEDIUM5.3In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as inpu...
CVE-2021-29776MEDIUM4.3IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's ...
CVE-2021-46423MEDIUM5.3Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker...
CVE-2021-41041MEDIUM5.3In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification w...
CVE-2021-36895MEDIUM6.1Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG ima...
CVE-2021-36867MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now