2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21698 | HIGH | 7.5 | 2.1% | Nov 4, 2021 | Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file ... |
| CVE-2021-21695 | HIGH | 8.8 | 2.1% | Nov 4, 2021 | FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Je... |
| CVE-2021-21688 | HIGH | 7.5 | 1.3% | Nov 4, 2021 | The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earli... |
| CVE-2021-21686 | HIGH | 8.1 | 1.9% | Nov 4, 2021 | File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do... |
| CVE-2021-40124 | HIGH | 7.8 | 0.2% | Nov 4, 2021 | A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could ... |
| CVE-2021-40120 | HIGH | 7.2 | 1.9% | Nov 4, 2021 | A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an a... |
| CVE-2021-40112 | HIGH | 7.5 | 1.4% | Nov 4, 2021 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie... |
| CVE-2021-34741 | HIGH | 7.5 | 1.2% | Nov 4, 2021 | A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could... |
| CVE-2021-34739 | HIGH | 8.1 | 1.6% | Nov 4, 2021 | A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an un... |
| CVE-2021-42624 | HIGH | 7.8 | 0.3% | Nov 4, 2021 | A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, w... |
| CVE-2021-34597 | HIGH | 7.8 | 0.6% | Nov 4, 2021 | Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an... |
| CVE-2021-43339 | HIGH | 8.8 | 9.6% | Nov 3, 2021 | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file... |
| CVE-2021-38424 | HIGH | 7.8 | 0.5% | Nov 3, 2021 | The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formula... |
| CVE-2021-38422 | HIGH | 7.8 | 0.2% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attac... |
| CVE-2021-38420 | HIGH | 7.8 | 0.2% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged us... |
| CVE-2021-38416 | HIGH | 7.8 | 0.2% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL ... |
| CVE-2021-35053 | HIGH | 7.5 | 2.5% | Nov 3, 2021 | Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change spe... |
| CVE-2021-33800 | HIGH | 7.5 | 1.5% | Nov 3, 2021 | In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal. |
| CVE-2021-26786 | HIGH | 8.8 | 1.5% | Nov 3, 2021 | An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbit... |
| CVE-2021-41585 | HIGH | 7.5 | 2.4% | Nov 3, 2021 | Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to m... |
| CVE-2021-38161 | HIGH | 8.1 | 1.9% | Nov 3, 2021 | Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle a... |
| CVE-2021-37149 | HIGH | 7.5 | 2.5% | Nov 3, 2021 | Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request... |
| CVE-2021-37148 | HIGH | 7.5 | 2.5% | Nov 3, 2021 | Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request... |
| CVE-2021-37147 | HIGH | 7.5 | 2.4% | Nov 3, 2021 | Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request... |
| CVE-2021-40848 | HIGH | 7.8 | 1.0% | Nov 3, 2021 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now