2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36828MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions.
CVE-2021-40425MEDIUM6.5An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A sp...
CVE-2021-40424MEDIUM6.5An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A sp...
CVE-2021-40405MEDIUM6.5A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_2...
CVE-2021-21967MEDIUM5.9An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 37...
CVE-2021-45228MEDIUM5.4An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the d...
CVE-2021-45227MEDIUM5.4An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file...
CVE-2021-43633MEDIUM5.4Sourcecodester Messaging Web Application 1.0 is vulnerable to stored XSS. If a sender inserts valid scripts into the cha...
CVE-2021-43288MEDIUM5.4An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious J...
CVE-2021-43154MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action i...
CVE-2021-43742MEDIUM5.4CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.
CVE-2021-28544MEDIUM4.3Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should b...
CVE-2021-41005MEDIUM6.5A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.
CVE-2021-39814MEDIUM6.7In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could l...
CVE-2021-39805MEDIUM6.5In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This coul...
CVE-2021-39804MEDIUM6.5In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persi...
CVE-2021-39803MEDIUM6.5In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remot...
CVE-2021-39800MEDIUM5.5In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead t...
CVE-2021-36914MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Man...
CVE-2021-43177MEDIUM5.3As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to re...
CVE-2021-36910MEDIUM4.8Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20.
CVE-2021-36896MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress p...
CVE-2021-36893MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress...
CVE-2021-36848MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versio...
CVE-2021-36846MEDIUM4.8Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now