2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41366 | HIGH | 7.8 | 0.4% | Nov 10, 2021 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
| CVE-2021-41356 | HIGH | 7.5 | 2.7% | Nov 10, 2021 | Windows Denial of Service Vulnerability |
| CVE-2021-40442 | HIGH | 7.8 | 2.1% | Nov 10, 2021 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2021-38666 | HIGH | 8.8 | 13.0% | Nov 10, 2021 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2021-38665 | HIGH | 7.4 | 6.2% | Nov 10, 2021 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
| CVE-2021-36957 | HIGH | 7.8 | 0.4% | Nov 10, 2021 | Windows Desktop Bridge Elevation of Privilege Vulnerability |
| CVE-2021-37158 | HIGH | 8.8 | 2.3% | Nov 10, 2021 | An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS c... |
| CVE-2021-37157 | HIGH | 8.8 | 1.3% | Nov 10, 2021 | An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root passwo... |
| CVE-2021-20119 | HIGH | 7.1 | 0.4% | Nov 9, 2021 | The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in us... |
| CVE-2021-43174 | HIGH | 7.5 | 1.2% | Nov 9, 2021 | NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP r... |
| CVE-2021-43173 | HIGH | 7.5 | 1.4% | Nov 9, 2021 | In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not ans... |
| CVE-2021-43172 | HIGH | 7.5 | 1.2% | Nov 9, 2021 | NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to ne... |
| CVE-2021-43182 | HIGH | 7.5 | 0.9% | Nov 9, 2021 | In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. |
| CVE-2021-43180 | HIGH | 7.5 | 1.0% | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. |
| CVE-2021-43203 | HIGH | 7.5 | 0.8% | Nov 9, 2021 | In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly. |
| CVE-2021-43196 | HIGH | 7.5 | 1.0% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. |
| CVE-2021-43189 | HIGH | 7.3 | 0.7% | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. |
| CVE-2021-43188 | HIGH | 7.3 | 0.7% | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. |
| CVE-2021-43114 | HIGH | 7.5 | 1.1% | Nov 9, 2021 | FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR... |
| CVE-2021-42021 | HIGH | 7.5 | 1.7% | Nov 9, 2021 | A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2),... |
| CVE-2021-40366 | HIGH | 7.4 | 0.4% | Nov 9, 2021 | A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module... |
| CVE-2021-40359 | HIGH | 7.7 | 1.1% | Nov 9, 2021 | A vulnerability has been identified in OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd4), OpenPCS... |
| CVE-2021-37207 | HIGH | 7.8 | 0.2% | Nov 9, 2021 | A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper... |
| CVE-2021-31888 | HIGH | 8.8 | 2.4% | Nov 9, 2021 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver... |
| CVE-2021-31887 | HIGH | 8.8 | 2.4% | Nov 9, 2021 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now