2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-30042MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont...
CVE-2021-30039MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo...
CVE-2021-30034MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
CVE-2021-30030MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
CVE-2021-29429MEDIUM5.5In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacke...
CVE-2021-21393MEDIUM6.5Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-21392MEDIUM6.3Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-3163MEDIUM6.1A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an ...
CVE-2021-22497HIGH7.2Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session managem...
CVE-2021-21394MEDIUM6.5Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-21545HIGH7.8Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could ...
CVE-2021-21524CRITICAL9.8Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerabi...
CVE-2021-3128HIGH7.5In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386...
CVE-2021-3125HIGH7.5In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, T...
CVE-2021-29357HIGH8.6The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime manage...
CVE-2021-29302HIGH8.1TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process i...
CVE-2021-23270HIGH7.5In Gargoyle OS 1.12.0, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an a...
CVE-2021-20519MEDIUM5.4IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2021-3465Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-27486HIGH7.8FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-b...
CVE-2021-24024MEDIUM6.5A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and ...
CVE-2021-22190MEDIUM6.5A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT t...
CVE-2021-25926MEDIUM6.1In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user inp...
CVE-2021-25925MEDIUM5.4in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not be...
CVE-2021-24231MEDIUM6.5The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now