2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42333 | HIGH | 8.8 | 1.1% | Oct 15, 2021 | The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL c... |
| CVE-2021-42330 | HIGH | 8.8 | 0.9% | Oct 15, 2021 | The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user... |
| CVE-2021-40999 | HIGH | 7.2 | 1.9% | Oct 15, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas... |
| CVE-2021-42340 | HIGH | 7.5 | 11.0% | Oct 14, 2021 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60... |
| CVE-2021-38295 | HIGH | 7.3 | 2.5% | Oct 14, 2021 | In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachmen... |
| CVE-2021-36389 | HIGH | 7.5 | 3.0% | Oct 14, 2021 | In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Ref... |
| CVE-2021-36388 | HIGH | 7.5 | 3.1% | Oct 14, 2021 | In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Obj... |
| CVE-2021-42369 | HIGH | 8.8 | 1.0% | Oct 14, 2021 | Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject ... |
| CVE-2021-42228 | HIGH | 8.8 | 1.0% | Oct 14, 2021 | A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.h... |
| CVE-2021-38346 | HIGH | 8.8 | 1.7% | Oct 14, 2021 | The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a locati... |
| CVE-2021-37933 | HIGH | 7.5 | 1.5% | Oct 14, 2021 | An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, r... |
| CVE-2021-33177 | HIGH | 8.8 | 9.8% | Oct 14, 2021 | The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation r... |
| CVE-2021-22964 | HIGH | 8.8 | 1.0% | Oct 14, 2021 | A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect... |
| CVE-2021-20599 | HIGH | 7.5 | 1.3% | Oct 14, 2021 | Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC i... |
| CVE-2021-42341 | HIGH | 7.5 | 2.0% | Oct 14, 2021 | checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the... |
| CVE-2021-40854 | HIGH | 7.8 | 0.2% | Oct 14, 2021 | AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Cha... |
| CVE-2021-40843 | HIGH | 7.3 | 0.4% | Oct 13, 2021 | Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An atta... |
| CVE-2021-20131 | HIGH | 8.8 | 16.0% | Oct 13, 2021 | ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope... |
| CVE-2021-20130 | HIGH | 8.8 | 31.6% | Oct 13, 2021 | ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope... |
| CVE-2021-3057 | HIGH | 8.1 | 1.4% | Oct 13, 2021 | A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the... |
| CVE-2021-20129 | HIGH | 7.5 | 1.6% | Oct 13, 2021 | An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to... |
| CVE-2021-20127 | HIGH | 8.1 | 1.1% | Oct 13, 2021 | An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek... |
| CVE-2021-20126 | HIGH | 8.8 | 0.6% | Oct 13, 2021 | Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a we... |
| CVE-2021-20124 | HIGH | 7.5 | 69.2% | Oct 13, 2021 | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the W... |
| CVE-2021-20123 | HIGH | 7.5 | 74.3% | Oct 13, 2021 | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the D... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now