2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-21698HIGH7.5Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file ...
CVE-2021-21695HIGH8.8FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Je...
CVE-2021-21688HIGH7.5The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earli...
CVE-2021-21686HIGH8.1File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do...
CVE-2021-40124HIGH7.8A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could ...
CVE-2021-40120HIGH7.2A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an a...
CVE-2021-40112HIGH7.5Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie...
CVE-2021-34741HIGH7.5A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could...
CVE-2021-34739HIGH8.1A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an un...
CVE-2021-42624HIGH7.8A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, w...
CVE-2021-34597HIGH7.8Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an...
CVE-2021-43339HIGH8.8In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file...
CVE-2021-38424HIGH7.8The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formula...
CVE-2021-38422HIGH7.8Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attac...
CVE-2021-38420HIGH7.8Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged us...
CVE-2021-38416HIGH7.8Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL ...
CVE-2021-35053HIGH7.5Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change spe...
CVE-2021-33800HIGH7.5In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
CVE-2021-26786HIGH8.8An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbit...
CVE-2021-41585HIGH7.5Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to m...
CVE-2021-38161HIGH8.1Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle a...
CVE-2021-37149HIGH7.5Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request...
CVE-2021-37148HIGH7.5Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request...
CVE-2021-37147HIGH7.5Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request...
CVE-2021-40848HIGH7.8In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now