2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30042 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont... |
| CVE-2021-30039 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo... |
| CVE-2021-30034 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php. |
| CVE-2021-30030 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php. |
| CVE-2021-29429 | MEDIUM | 5.5 | 0.5% | Apr 12, 2021 | In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacke... |
| CVE-2021-21393 | MEDIUM | 6.5 | 1.6% | Apr 12, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-21392 | MEDIUM | 6.3 | 0.9% | Apr 12, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-3163 | MEDIUM | 6.1 | 1.3% | Apr 12, 2021 | A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an ... |
| CVE-2021-22497 | HIGH | 7.2 | 0.8% | Apr 12, 2021 | Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session managem... |
| CVE-2021-21394 | MEDIUM | 6.5 | 1.5% | Apr 12, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-21545 | HIGH | 7.8 | 0.3% | Apr 12, 2021 | Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could ... |
| CVE-2021-21524 | CRITICAL | 9.8 | 3.2% | Apr 12, 2021 | Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerabi... |
| CVE-2021-3128 | HIGH | 7.5 | 2.2% | Apr 12, 2021 | In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386... |
| CVE-2021-3125 | HIGH | 7.5 | 1.5% | Apr 12, 2021 | In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, T... |
| CVE-2021-29357 | HIGH | 8.6 | 1.0% | Apr 12, 2021 | The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime manage... |
| CVE-2021-29302 | HIGH | 8.1 | 5.9% | Apr 12, 2021 | TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process i... |
| CVE-2021-23270 | HIGH | 7.5 | 1.0% | Apr 12, 2021 | In Gargoyle OS 1.12.0, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an a... |
| CVE-2021-20519 | MEDIUM | 5.4 | 0.6% | Apr 12, 2021 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary... |
| CVE-2021-3465 | — | — | — | Apr 12, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-27486 | HIGH | 7.8 | 1.0% | Apr 12, 2021 | FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-b... |
| CVE-2021-24024 | MEDIUM | 6.5 | 0.9% | Apr 12, 2021 | A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and ... |
| CVE-2021-22190 | MEDIUM | 6.5 | 1.3% | Apr 12, 2021 | A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT t... |
| CVE-2021-25926 | MEDIUM | 6.1 | 0.8% | Apr 12, 2021 | In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user inp... |
| CVE-2021-25925 | MEDIUM | 5.4 | 0.7% | Apr 12, 2021 | in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not be... |
| CVE-2021-24231 | MEDIUM | 6.5 | 0.6% | Apr 12, 2021 | The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now