2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41792 | MEDIUM | 5.3 | 0.8% | Oct 21, 2021 | An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-tran... |
| CVE-2021-41791 | MEDIUM | 5.4 | 0.5% | Oct 21, 2021 | An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An ev... |
| CVE-2021-40123 | MEDIUM | 6.5 | 0.8% | Oct 21, 2021 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2021-40121 | MEDIUM | 4.8 | 0.4% | Oct 21, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could al... |
| CVE-2021-39127 | MEDIUM | 5.3 | 1.3% | Oct 21, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL e... |
| CVE-2021-39126 | MEDIUM | 6.5 | 0.7% | Oct 21, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cros... |
| CVE-2021-34789 | MEDIUM | 4.8 | 0.6% | Oct 21, 2021 | A vulnerability in the web-based management interface of Cisco Tetration could allow an authenticated, remote attacker t... |
| CVE-2021-34760 | MEDIUM | 4.8 | 0.6% | Oct 21, 2021 | A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow ... |
| CVE-2021-34738 | MEDIUM | 6.1 | 0.6% | Oct 21, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could al... |
| CVE-2021-42096 | MEDIUM | 4.3 | 1.2% | Oct 21, 2021 | GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin pa... |
| CVE-2021-42299 | MEDIUM | 5.6 | 0.7% | Oct 20, 2021 | Microsoft Surface Pro 3 Security Feature Bypass Vulnerability |
| CVE-2021-42762 | MEDIUM | 5.3 | 0.5% | Oct 20, 2021 | BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed... |
| CVE-2021-38896 | MEDIUM | 6.1 | 0.6% | Oct 20, 2021 | IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2021-41135 | MEDIUM | 6.5 | 1.7% | Oct 20, 2021 | The Cosmos-SDK is a framework for building blockchain applications in Golang. Affected versions of the SDK were vulnerab... |
| CVE-2021-21745 | MEDIUM | 4.3 | 55.7% | Oct 20, 2021 | ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use th... |
| CVE-2021-21743 | MEDIUM | 4.3 | 0.8% | Oct 20, 2021 | ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP re... |
| CVE-2021-21747 | MEDIUM | 6.1 | 0.6% | Oct 20, 2021 | ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie informatio... |
| CVE-2021-21746 | MEDIUM | 6.1 | 0.6% | Oct 20, 2021 | ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie informatio... |
| CVE-2021-25972 | MEDIUM | 4.9 | 1.0% | Oct 20, 2021 | In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload fea... |
| CVE-2021-25971 | MEDIUM | 4.3 | 1.0% | Oct 20, 2021 | In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes... |
| CVE-2021-25969 | MEDIUM | 6.1 | 0.8% | Oct 20, 2021 | In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attack... |
| CVE-2021-35666 | MEDIUM | 5.9 | 1.2% | Oct 20, 2021 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported vers... |
| CVE-2021-35665 | MEDIUM | 6.1 | 0.8% | Oct 20, 2021 | Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported vers... |
| CVE-2021-35655 | MEDIUM | 5.3 | 1.1% | Oct 20, 2021 | Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported v... |
| CVE-2021-35650 | MEDIUM | 4.6 | 0.6% | Oct 20, 2021 | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported ve... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now