2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-1470MEDIUM4.9A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated...
CVE-2021-1466MEDIUM5.4A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacke...
CVE-2021-1464MEDIUM5A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorizat...
CVE-2021-3991MEDIUM4.3An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricte...
CVE-2021-3988MEDIUM6.1A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The...
CVE-2021-3987MEDIUM4.3An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without publi...
CVE-2021-3986MEDIUM4.3A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to othe...
CVE-2021-3841MEDIUM5.4sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through ...
CVE-2021-3741MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2...
CVE-2021-3740MEDIUM6.8A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidat...
CVE-2021-27704MEDIUM6.5Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.
CVE-2021-27703MEDIUM5.4Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.
CVE-2021-27701MEDIUM4.7SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The applic...
CVE-2021-4452MEDIUM5.4The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple paramet...
CVE-2021-4446MEDIUM4.3The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and incl...
CVE-2021-4445MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and i...
CVE-2021-37577MEDIUM6.8Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetoo...
CVE-2021-27917MEDIUM5.4Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
CVE-2021-38133MEDIUM6.5Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact al...
CVE-2021-38131MEDIUM6.1Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.
CVE-2021-22518MEDIUM5.5A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information in...
CVE-2021-22503MEDIUM6.1Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered i...
CVE-2021-4442MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity tests to TCP_QUEUE_SEQ Qingyu Li r...
CVE-2021-22529MEDIUM5.5A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects N...
CVE-2021-22509MEDIUM6.5A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now