2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-34794MEDIUM5.3A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adapt...
CVE-2021-34791MEDIUM5.3Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cis...
CVE-2021-34790MEDIUM5.3Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cis...
CVE-2021-34787MEDIUM5.3A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA)...
CVE-2021-34764MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could...
CVE-2021-34763MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could...
CVE-2021-34761MEDIUM6A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwri...
CVE-2021-3900MEDIUM6.5firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-37808MEDIUM5.9SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcateg...
CVE-2021-37806MEDIUM5.9An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. ...
CVE-2021-37805MEDIUM5.4A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected vers...
CVE-2021-29868MEDIUM5.5IBM i2 iBase 8.9.13 and 9.0.0 could allow a local attacker to obtain sensitive information due to insufficient session e...
CVE-2021-29786MEDIUM6.5IBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Fo...
CVE-2021-29713MEDIUM5.4IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2021-29673MEDIUM5.4IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2021-20526MEDIUM5.3IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t...
CVE-2021-38379MEDIUM5.5The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
CVE-2021-36756MEDIUM6.5CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
CVE-2021-41590MEDIUM5.3In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration ...
CVE-2021-37131MEDIUM6.8There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high pri...
CVE-2021-37124MEDIUM6.5There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special char...
CVE-2021-37122MEDIUM6.5There is a use-after-free (UAF) vulnerability in Huawei products. An attacker may craft specific packets to exploit this...
CVE-2021-35236MEDIUM5.3The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tel...
CVE-2021-35235MEDIUM5.3The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote...
CVE-2021-35233MEDIUM5.3The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diag...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now