2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43461 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter. |
| CVE-2021-43459 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parame... |
| CVE-2021-25113 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its sett... |
| CVE-2021-25048 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creatin... |
| CVE-2021-33616 | MEDIUM | 5.4 | 0.7% | Apr 4, 2022 | RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS. |
| CVE-2021-30066 | MEDIUM | 6.8 | 0.2% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ... |
| CVE-2021-30061 | MEDIUM | 6.8 | 0.4% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ... |
| CVE-2021-32503 | MEDIUM | 4.9 | 0.8% | Apr 1, 2022 | Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users... |
| CVE-2021-27493 | MEDIUM | 6.5 | 0.7% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well... |
| CVE-2021-27223 | MEDIUM | 5.5 | 0.2% | Apr 1, 2022 | A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and ... |
| CVE-2021-23288 | MEDIUM | 4.8 | 0.3% | Apr 1, 2022 | The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacke... |
| CVE-2021-23287 | MEDIUM | 5.4 | 0.4% | Apr 1, 2022 | The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issu... |
| CVE-2021-20295 | MEDIUM | 6.5 | 0.3% | Apr 1, 2022 | It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-... |
| CVE-2021-30331 | MEDIUM | 5.5 | 0.1% | Apr 1, 2022 | Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto... |
| CVE-2021-43707 | MEDIUM | 6.1 | 0.6% | Mar 31, 2022 | Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. |
| CVE-2021-43478 | MEDIUM | 5.4 | 0.8% | Mar 31, 2022 | A vulnerability exists in Hoosk 1.8.0 in /install/index.php, due to a failure to check if config.php already exists in t... |
| CVE-2021-42946 | MEDIUM | 4.8 | 0.5% | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page. |
| CVE-2021-42869 | MEDIUM | 4.8 | 0.5% | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parame... |
| CVE-2021-42868 | MEDIUM | 4.8 | 0.8% | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parame... |
| CVE-2021-42867 | MEDIUM | 4.8 | 0.6% | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, ... |
| CVE-2021-42866 | MEDIUM | 4.8 | 0.5% | Mar 31, 2022 | A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.... |
| CVE-2021-43505 | MEDIUM | 5.4 | 0.5% | Mar 31, 2022 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) ... |
| CVE-2021-20729 | MEDIUM | 6.1 | 2.8% | Mar 31, 2022 | Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and p... |
| CVE-2021-43662 | MEDIUM | 6.5 | 0.5% | Mar 31, 2022 | totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontroll... |
| CVE-2021-43661 | MEDIUM | 6.1 | 0.6% | Mar 31, 2022 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now