2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43575 | MEDIUM | 5.5 | 0.3% | Nov 9, 2021 | KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local use... |
| CVE-2021-35489 | MEDIUM | 6.1 | 0.8% | Nov 9, 2021 | Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected... |
| CVE-2021-35488 | MEDIUM | 6.1 | 2.6% | Nov 9, 2021 | Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title paramete... |
| CVE-2021-43181 | MEDIUM | 6.1 | 0.6% | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, stored XSS is possible. |
| CVE-2021-43201 | MEDIUM | 5.3 | 0.7% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project. |
| CVE-2021-43199 | MEDIUM | 5.3 | 0.6% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient. |
| CVE-2021-43198 | MEDIUM | 5.4 | 0.4% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, stored XSS is possible. |
| CVE-2021-43197 | MEDIUM | 6.1 | 0.6% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS. |
| CVE-2021-43195 | MEDIUM | 5.3 | 0.7% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing. |
| CVE-2021-43194 | MEDIUM | 5.3 | 0.8% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, user enumeration was possible. |
| CVE-2021-43192 | MEDIUM | 5.3 | 0.7% | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. |
| CVE-2021-43191 | MEDIUM | 5.3 | 0.7% | Nov 9, 2021 | JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. |
| CVE-2021-43190 | MEDIUM | 5.3 | 0.7% | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. |
| CVE-2021-43187 | MEDIUM | 5.3 | 0.8% | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. |
| CVE-2021-43186 | MEDIUM | 5.4 | 0.5% | Nov 9, 2021 | JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. |
| CVE-2021-43184 | MEDIUM | 5.4 | 0.6% | Nov 9, 2021 | In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. |
| CVE-2021-3641 | MEDIUM | 6.1 | 0.3% | Nov 9, 2021 | Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoi... |
| CVE-2021-43519 | MEDIUM | 5.5 | 1.1% | Nov 9, 2021 | Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via... |
| CVE-2021-42026 | MEDIUM | 4.3 | 0.5% | Nov 9, 2021 | A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications... |
| CVE-2021-42025 | MEDIUM | 6.5 | 0.6% | Nov 9, 2021 | A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications... |
| CVE-2021-42015 | MEDIUM | 5.5 | 0.2% | Nov 9, 2021 | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications... |
| CVE-2021-40364 | MEDIUM | 5.5 | 0.2% | Nov 9, 2021 | A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC... |
| CVE-2021-31344 | MEDIUM | 5.3 | 1.4% | Nov 9, 2021 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R... |
| CVE-2021-40261 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via th... |
| CVE-2021-40260 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester Tailor Management 1.0 via the (1) eid parame... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now