2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3950 | MEDIUM | 5.4 | 0.8% | Nov 19, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3976 | MEDIUM | 6.5 | 0.4% | Nov 19, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-41532 | MEDIUM | 5.3 | 2.3% | Nov 19, 2021 | In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any un... |
| CVE-2021-39235 | MEDIUM | 6.5 | 1.5% | Nov 19, 2021 | In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated u... |
| CVE-2021-39234 | MEDIUM | 6.8 | 1.4% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific requ... |
| CVE-2021-44033 | MEDIUM | 6.8 | 0.5% | Nov 19, 2021 | In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed. |
| CVE-2021-44025 | MEDIUM | 6.1 | 1.0% | Nov 19, 2021 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when disp... |
| CVE-2021-41278 | MEDIUM | 5.7 | 0.3% | Nov 19, 2021 | Functions SDK for EdgeX is meant to provide all the plumbing necessary for developers to get started in processing/trans... |
| CVE-2021-40131 | MEDIUM | 5.4 | 0.7% | Nov 19, 2021 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an ... |
| CVE-2021-40130 | MEDIUM | 4.9 | 1.1% | Nov 19, 2021 | A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, ... |
| CVE-2021-40129 | MEDIUM | 4.9 | 1.0% | Nov 19, 2021 | A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authent... |
| CVE-2021-43017 | MEDIUM | 4.2 | 1.1% | Nov 18, 2021 | Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Cre... |
| CVE-2021-23193 | MEDIUM | 6.5 | 0.7% | Nov 18, 2021 | Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unp... |
| CVE-2021-23167 | MEDIUM | 6.8 | 0.4% | Nov 18, 2021 | Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive infor... |
| CVE-2021-23155 | MEDIUM | 6.8 | 0.5% | Nov 18, 2021 | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the l... |
| CVE-2021-42268 | MEDIUM | 5.5 | 1.8% | Nov 18, 2021 | Adobe Animate version 21.0.9 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specia... |
| CVE-2021-40761 | MEDIUM | 5.5 | 1.3% | Nov 18, 2021 | Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a ... |
| CVE-2021-40756 | MEDIUM | 5.5 | 1.3% | Nov 18, 2021 | Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a ... |
| CVE-2021-43668 | MEDIUM | 5.5 | 0.3% | Nov 18, 2021 | Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They wi... |
| CVE-2021-37938 | MEDIUM | 4.3 | 0.7% | Nov 18, 2021 | It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which ... |
| CVE-2021-43549 | MEDIUM | 4.8 | 0.7% | Nov 18, 2021 | A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API e... |
| CVE-2021-27026 | MEDIUM | 4.4 | 0.2% | Nov 18, 2021 | A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged |
| CVE-2021-27025 | MEDIUM | 6.5 | 1.1% | Nov 18, 2021 | A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Deni... |
| CVE-2021-0672 | MEDIUM | 5.5 | 0.1% | Nov 18, 2021 | In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local i... |
| CVE-2021-0671 | MEDIUM | 6.7 | 0.1% | Nov 18, 2021 | In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of p... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now