2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25909HIGH7.5ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause ...
CVE-2021-25123HIGH7.8The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Clou...
CVE-2021-3176HIGH8The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could ...
CVE-2021-3298MEDIUM5.4Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit ...
CVE-2021-3336HIGH8.1DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavio...
CVE-2021-26308HIGH7.5An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to ...
CVE-2021-26307MEDIUM5.5An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the proces...
CVE-2021-26306HIGH7.5An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() ...
CVE-2021-26305CRITICAL9.8An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implement...
CVE-2021-26304MEDIUM5.4PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.
CVE-2021-26303MEDIUM6.1PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.
CVE-2021-3341HIGH7.5A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5...
CVE-2021-3337HIGH7.5The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading re...
CVE-2021-3160CRITICAL9.8Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product ...
CVE-2021-20185MEDIUM5.3It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit wh...
CVE-2021-25647MEDIUM5.4Mobile application "Testes de Codigo" v11.3 and prior allows stored XSS by injecting a payload in the "feedback" message...
CVE-2021-20187HIGH7.2It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to ex...
CVE-2021-20186MEDIUM5.4It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, addit...
CVE-2021-20184MEDIUM4.3It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade relate...
CVE-2021-20183MEDIUM5.4It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficien...
CVE-2021-22875MEDIUM6.1Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.
CVE-2021-22874MEDIUM6.1Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset`...
CVE-2021-20622MEDIUM6.1Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0....
CVE-2021-20621HIGH8.8Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 fir...
CVE-2021-20620MEDIUM6.1Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now