2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-43461MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.
CVE-2021-43459MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parame...
CVE-2021-25113MEDIUM5.4The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its sett...
CVE-2021-25048MEDIUM5.4The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creatin...
CVE-2021-33616MEDIUM5.4RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.
CVE-2021-30066MEDIUM6.8On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ...
CVE-2021-30061MEDIUM6.8On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ...
CVE-2021-32503MEDIUM4.9Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users...
CVE-2021-27493MEDIUM6.5Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well...
CVE-2021-27223MEDIUM5.5A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and ...
CVE-2021-23288MEDIUM4.8The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacke...
CVE-2021-23287MEDIUM5.4The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issu...
CVE-2021-20295MEDIUM6.5It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-...
CVE-2021-30331MEDIUM5.5Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto...
CVE-2021-43707MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
CVE-2021-43478MEDIUM5.4A vulnerability exists in Hoosk 1.8.0 in /install/index.php, due to a failure to check if config.php already exists in t...
CVE-2021-42946MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.
CVE-2021-42869MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parame...
CVE-2021-42868MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parame...
CVE-2021-42867MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, ...
CVE-2021-42866MEDIUM4.8A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting....
CVE-2021-43505MEDIUM5.4Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) ...
CVE-2021-20729MEDIUM6.1Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and p...
CVE-2021-43662MEDIUM6.5totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontroll...
CVE-2021-43661MEDIUM6.1totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now