2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34794 | MEDIUM | 5.3 | 0.9% | Oct 27, 2021 | A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adapt... |
| CVE-2021-34791 | MEDIUM | 5.3 | 1.1% | Oct 27, 2021 | Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cis... |
| CVE-2021-34790 | MEDIUM | 5.3 | 1.1% | Oct 27, 2021 | Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cis... |
| CVE-2021-34787 | MEDIUM | 5.3 | 1.0% | Oct 27, 2021 | A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA)... |
| CVE-2021-34764 | MEDIUM | 6.1 | 0.6% | Oct 27, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could... |
| CVE-2021-34763 | MEDIUM | 4.8 | 0.5% | Oct 27, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could... |
| CVE-2021-34761 | MEDIUM | 6 | 0.2% | Oct 27, 2021 | A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwri... |
| CVE-2021-3900 | MEDIUM | 6.5 | 0.5% | Oct 27, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-37808 | MEDIUM | 5.9 | 1.8% | Oct 27, 2021 | SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcateg... |
| CVE-2021-37806 | MEDIUM | 5.9 | 1.8% | Oct 27, 2021 | An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. ... |
| CVE-2021-37805 | MEDIUM | 5.4 | 0.6% | Oct 27, 2021 | A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected vers... |
| CVE-2021-29868 | MEDIUM | 5.5 | 0.2% | Oct 27, 2021 | IBM i2 iBase 8.9.13 and 9.0.0 could allow a local attacker to obtain sensitive information due to insufficient session e... |
| CVE-2021-29786 | MEDIUM | 6.5 | 0.5% | Oct 27, 2021 | IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Fo... |
| CVE-2021-29713 | MEDIUM | 5.4 | 0.5% | Oct 27, 2021 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary... |
| CVE-2021-29673 | MEDIUM | 5.4 | 0.5% | Oct 27, 2021 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary... |
| CVE-2021-20526 | MEDIUM | 5.3 | 1.1% | Oct 27, 2021 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t... |
| CVE-2021-38379 | MEDIUM | 5.5 | 0.2% | Oct 27, 2021 | The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. |
| CVE-2021-36756 | MEDIUM | 6.5 | 0.4% | Oct 27, 2021 | CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. |
| CVE-2021-41590 | MEDIUM | 5.3 | 0.8% | Oct 27, 2021 | In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration ... |
| CVE-2021-37131 | MEDIUM | 6.8 | 0.6% | Oct 27, 2021 | There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high pri... |
| CVE-2021-37124 | MEDIUM | 6.5 | 0.3% | Oct 27, 2021 | There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special char... |
| CVE-2021-37122 | MEDIUM | 6.5 | 0.3% | Oct 27, 2021 | There is a use-after-free (UAF) vulnerability in Huawei products. An attacker may craft specific packets to exploit this... |
| CVE-2021-35236 | MEDIUM | 5.3 | 0.5% | Oct 27, 2021 | The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tel... |
| CVE-2021-35235 | MEDIUM | 5.3 | 1.2% | Oct 27, 2021 | The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote... |
| CVE-2021-35233 | MEDIUM | 5.3 | 0.9% | Oct 27, 2021 | The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diag... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now