2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-4149MEDIUM5.5A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock op...
CVE-2021-4148MEDIUM5.5A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity ...
CVE-2021-27430MEDIUM6.8GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with phy...
CVE-2021-27424MEDIUM5.3GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made ...
CVE-2021-27420MEDIUM5.3GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs...
CVE-2021-27418MEDIUM6.1GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly...
CVE-2021-43737MEDIUM6.5An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account...
CVE-2021-25220MEDIUM6.8BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16....
CVE-2021-33961MEDIUM6.1A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter.
CVE-2021-38745MEDIUM6.8Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execu...
CVE-2021-46390MEDIUM6.8An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and ...
CVE-2021-25019MEDIUM6.1The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it b...
CVE-2021-45117MEDIUM6.5The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointe...
CVE-2021-44760MEDIUM5.4Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 vers...
CVE-2021-27789MEDIUM6.5The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements...
CVE-2021-23209MEDIUM4.8Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP ...
CVE-2021-23150MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pag...
CVE-2021-39046MEDIUM4.9IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user cre...
CVE-2021-29899MEDIUM6.5IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of ser...
CVE-2021-22571MEDIUM5.5A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process ...
CVE-2021-45868MEDIUM5.5In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk)....
CVE-2021-43961MEDIUM4.3Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
CVE-2021-44261MEDIUM5.3A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote at...
CVE-2021-23771MEDIUM6.5This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox E...
CVE-2021-45792MEDIUM4.8Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now