2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25909 | HIGH | 7.5 | 1.3% | Jan 29, 2021 | ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause ... |
| CVE-2021-25123 | HIGH | 7.8 | 0.3% | Jan 29, 2021 | The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Clou... |
| CVE-2021-3176 | HIGH | 8 | 0.9% | Jan 29, 2021 | The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could ... |
| CVE-2021-3298 | MEDIUM | 5.4 | 2.1% | Jan 29, 2021 | Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit ... |
| CVE-2021-3336 | HIGH | 8.1 | 0.8% | Jan 29, 2021 | DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavio... |
| CVE-2021-26308 | HIGH | 7.5 | 1.5% | Jan 29, 2021 | An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to ... |
| CVE-2021-26307 | MEDIUM | 5.5 | 0.3% | Jan 29, 2021 | An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the proces... |
| CVE-2021-26306 | HIGH | 7.5 | 1.3% | Jan 29, 2021 | An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() ... |
| CVE-2021-26305 | CRITICAL | 9.8 | 1.7% | Jan 29, 2021 | An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implement... |
| CVE-2021-26304 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter. |
| CVE-2021-26303 | MEDIUM | 6.1 | 0.8% | Jan 29, 2021 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field. |
| CVE-2021-3341 | HIGH | 7.5 | 1.3% | Jan 29, 2021 | A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5... |
| CVE-2021-3337 | HIGH | 7.5 | 11.5% | Jan 28, 2021 | The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading re... |
| CVE-2021-3160 | CRITICAL | 9.8 | 4.7% | Jan 28, 2021 | Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product ... |
| CVE-2021-20185 | MEDIUM | 5.3 | 1.4% | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit wh... |
| CVE-2021-25647 | MEDIUM | 5.4 | 0.7% | Jan 28, 2021 | Mobile application "Testes de Codigo" v11.3 and prior allows stored XSS by injecting a payload in the "feedback" message... |
| CVE-2021-20187 | HIGH | 7.2 | 1.6% | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to ex... |
| CVE-2021-20186 | MEDIUM | 5.4 | 0.8% | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, addit... |
| CVE-2021-20184 | MEDIUM | 4.3 | 0.7% | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade relate... |
| CVE-2021-20183 | MEDIUM | 5.4 | 0.8% | Jan 28, 2021 | It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficien... |
| CVE-2021-22875 | MEDIUM | 6.1 | 22.1% | Jan 28, 2021 | Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter. |
| CVE-2021-22874 | MEDIUM | 6.1 | 22.1% | Jan 28, 2021 | Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset`... |
| CVE-2021-20622 | MEDIUM | 6.1 | 1.0% | Jan 28, 2021 | Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.... |
| CVE-2021-20621 | HIGH | 8.8 | 0.6% | Jan 28, 2021 | Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 fir... |
| CVE-2021-20620 | MEDIUM | 6.1 | 1.0% | Jan 28, 2021 | Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now