2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41158 | HIGH | 7.5 | 0.8% | Oct 26, 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2021-37364 | HIGH | 7.8 | 1.3% | Oct 26, 2021 | OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify perm... |
| CVE-2021-37363 | HIGH | 7.8 | 1.6% | Oct 26, 2021 | An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.e... |
| CVE-2021-41078 | HIGH | 7.8 | 1.5% | Oct 26, 2021 | Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file. |
| CVE-2021-37372 | HIGH | 8.8 | 3.3% | Oct 26, 2021 | Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can uplo... |
| CVE-2021-26609 | HIGH | 7.5 | 1.7% | Oct 26, 2021 | A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type paramete... |
| CVE-2021-40345 | HIGH | 7.2 | 23.0% | Oct 26, 2021 | An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can uplo... |
| CVE-2021-40344 | HIGH | 7.2 | 66.2% | Oct 26, 2021 | An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can uplo... |
| CVE-2021-40343 | HIGH | 7.8 | 0.7% | Oct 26, 2021 | An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios u... |
| CVE-2021-34595 | HIGH | 8.1 | 0.9% | Oct 26, 2021 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 ... |
| CVE-2021-34593 | HIGH | 7.5 | 2.6% | Oct 26, 2021 | In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid reque... |
| CVE-2021-34586 | HIGH | 7.5 | 13.1% | Oct 26, 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the ... |
| CVE-2021-34585 | HIGH | 7.5 | 0.9% | Oct 26, 2021 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser... |
| CVE-2021-34583 | HIGH | 7.5 | 8.4% | Oct 26, 2021 | Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service cond... |
| CVE-2021-41307 | HIGH | 7.5 | 1.6% | Oct 26, 2021 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of p... |
| CVE-2021-41306 | HIGH | 7.5 | 1.6% | Oct 26, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and ... |
| CVE-2021-41305 | HIGH | 7.5 | 1.2% | Oct 26, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private... |
| CVE-2021-41177 | HIGH | 8.1 | 1.5% | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud... |
| CVE-2021-41145 | HIGH | 7.5 | 1.6% | Oct 25, 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2021-41105 | HIGH | 7.5 | 2.4% | Oct 25, 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2021-39225 | HIGH | 8.1 | 1.3% | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.... |
| CVE-2021-38260 | HIGH | 7.8 | 0.3% | Oct 25, 2021 | NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDe... |
| CVE-2021-38258 | HIGH | 7.8 | 0.3% | Oct 25, 2021 | NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback(). |
| CVE-2021-34864 | HIGH | 8.8 | 0.2% | Oct 25, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (... |
| CVE-2021-34863 | HIGH | 8.8 | 1.4% | Oct 25, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now