2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22055MEDIUM5.3The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attacke...
CVE-2021-39068MEDIUM5.4IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows us...
CVE-2021-37293MEDIUM6.5A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page...
CVE-2021-25090MEDIUM5.4The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in vari...
CVE-2021-24987MEDIUM6.1The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape t...
CVE-2021-24986MEDIUM6.1The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attri...
CVE-2021-32161MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.
CVE-2021-32160MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.
CVE-2021-32158MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
CVE-2021-43009MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the reque...
CVE-2021-36293MEDIUM6.7Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin...
CVE-2021-36290MEDIUM6.7Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin...
CVE-2021-46437MEDIUM4.8An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.
CVE-2021-43432MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in p...
CVE-2021-41026MEDIUM6.5A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacke...
CVE-2021-32585MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow...
CVE-2021-43205MEDIUM5.3An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7...
CVE-2021-32593MEDIUM6.5A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN be...
CVE-2021-40375MEDIUM6.5Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having t...
CVE-2021-40374MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patien...
CVE-2021-45892MEDIUM5.9An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.
CVE-2021-45894MEDIUM5.9An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.
CVE-2021-36851MEDIUM5.4Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – ...
CVE-2021-36826MEDIUM5.4Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerabi...
CVE-2021-43462MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now