2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3909 | HIGH | 7.5 | 1.5% | Nov 11, 2021 | OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRP... |
| CVE-2021-3908 | HIGH | 7.5 | 0.7% | Nov 11, 2021 | OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, the... |
| CVE-2021-26558 | HIGH | 7.5 | 2.4% | Nov 11, 2021 | Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link reso... |
| CVE-2021-25980 | HIGH | 8.8 | 1.2% | Nov 11, 2021 | In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 an... |
| CVE-2021-43397 | HIGH | 8.8 | 3.7% | Nov 11, 2021 | LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin. |
| CVE-2021-40873 | HIGH | 7.5 | 1.3% | Nov 10, 2021 | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40.... |
| CVE-2021-40872 | HIGH | 7.5 | 1.5% | Nov 10, 2021 | An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a den... |
| CVE-2021-40871 | HIGH | 7.5 | 1.3% | Nov 10, 2021 | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial ... |
| CVE-2021-32023 | HIGH | 7.8 | 0.3% | Nov 10, 2021 | An elevation of privilege vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574... |
| CVE-2021-32021 | HIGH | 7.8 | 0.3% | Nov 10, 2021 | A denial of service vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574 and e... |
| CVE-2021-22048 | HIGH | 8.8 | 10.0% | Nov 10, 2021 | The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authenti... |
| CVE-2021-3063 | HIGH | 7.5 | 0.9% | Nov 10, 2021 | An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gatew... |
| CVE-2021-3062 | HIGH | 8.8 | 0.7% | Nov 10, 2021 | An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProte... |
| CVE-2021-3061 | HIGH | 7.2 | 0.9% | Nov 10, 2021 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authentic... |
| CVE-2021-3060 | HIGH | 8.1 | 33.9% | Nov 10, 2021 | An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software al... |
| CVE-2021-3059 | HIGH | 8.1 | 1.5% | Nov 10, 2021 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynam... |
| CVE-2021-3058 | HIGH | 7.2 | 1.6% | Nov 10, 2021 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administra... |
| CVE-2021-3056 | HIGH | 8.8 | 1.5% | Nov 10, 2021 | A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated att... |
| CVE-2021-43564 | HIGH | 7.5 | 1.0% | Nov 10, 2021 | An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extens... |
| CVE-2021-43563 | HIGH | 8.8 | 1.0% | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Cont... |
| CVE-2021-41426 | HIGH | 8.8 | 0.7% | Nov 10, 2021 | Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm. |
| CVE-2021-40503 | HIGH | 7.8 | 0.2% | Nov 10, 2021 | An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an ... |
| CVE-2021-40502 | HIGH | 8.8 | 0.8% | Nov 10, 2021 | SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authen... |
| CVE-2021-40501 | HIGH | 8.1 | 0.7% | Nov 10, 2021 | SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authe... |
| CVE-2021-43562 | HIGH | 8.8 | 1.3% | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension f... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now