2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1470 | MEDIUM | 4.9 | 1.0% | Nov 15, 2024 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated... |
| CVE-2021-1466 | MEDIUM | 5.4 | 0.6% | Nov 15, 2024 | A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacke... |
| CVE-2021-1464 | MEDIUM | 5 | 1.3% | Nov 15, 2024 | A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorizat... |
| CVE-2021-3991 | MEDIUM | 4.3 | 0.3% | Nov 15, 2024 | An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricte... |
| CVE-2021-3988 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The... |
| CVE-2021-3987 | MEDIUM | 4.3 | 0.3% | Nov 15, 2024 | An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without publi... |
| CVE-2021-3986 | MEDIUM | 4.3 | 0.4% | Nov 15, 2024 | A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to othe... |
| CVE-2021-3841 | MEDIUM | 5.4 | 0.2% | Nov 15, 2024 | sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through ... |
| CVE-2021-3741 | MEDIUM | 5.4 | 0.3% | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2... |
| CVE-2021-3740 | MEDIUM | 6.8 | 0.2% | Nov 15, 2024 | A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidat... |
| CVE-2021-27704 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page. |
| CVE-2021-27703 | MEDIUM | 5.4 | 0.2% | Nov 12, 2024 | Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page. |
| CVE-2021-27701 | MEDIUM | 4.7 | 0.2% | Nov 12, 2024 | SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The applic... |
| CVE-2021-4452 | MEDIUM | 5.4 | 0.5% | Oct 16, 2024 | The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple paramet... |
| CVE-2021-4446 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and incl... |
| CVE-2021-4445 | MEDIUM | 4.3 | 0.4% | Oct 16, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and i... |
| CVE-2021-37577 | MEDIUM | 6.8 | 0.2% | Oct 1, 2024 | Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetoo... |
| CVE-2021-27917 | MEDIUM | 5.4 | 0.3% | Sep 18, 2024 | Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. |
| CVE-2021-38133 | MEDIUM | 6.5 | 0.3% | Sep 12, 2024 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact al... |
| CVE-2021-38131 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000. |
| CVE-2021-22518 | MEDIUM | 5.5 | 0.1% | Sep 12, 2024 | A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information in... |
| CVE-2021-22503 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered i... |
| CVE-2021-4442 | MEDIUM | 5.5 | 0.4% | Aug 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity tests to TCP_QUEUE_SEQ Qingyu Li r... |
| CVE-2021-22529 | MEDIUM | 5.5 | 0.2% | Aug 28, 2024 | A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects N... |
| CVE-2021-22509 | MEDIUM | 6.5 | 0.2% | Aug 28, 2024 | A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now