2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41947 | HIGH | 7.2 | 1.1% | Oct 8, 2021 | A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode. |
| CVE-2021-42095 | HIGH | 7.5 | 0.9% | Oct 7, 2021 | Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar. |
| CVE-2021-42089 | HIGH | 7.5 | 1.1% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information. |
| CVE-2021-42086 | HIGH | 8.8 | 1.1% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a c... |
| CVE-2021-42093 | HIGH | 7.2 | 1.3% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manip... |
| CVE-2021-20584 | HIGH | 7.5 | 1.3% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by imp... |
| CVE-2021-20489 | HIGH | 8.8 | 0.4% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attac... |
| CVE-2021-40726 | HIGH | 7.8 | 5.1% | Oct 7, 2021 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a... |
| CVE-2021-40725 | HIGH | 7.8 | 5.1% | Oct 7, 2021 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a... |
| CVE-2021-28129 | HIGH | 7.8 | 0.5% | Oct 7, 2021 | While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but ins... |
| CVE-2021-41794 | HIGH | 7.5 | 1.2% | Oct 7, 2021 | ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer... |
| CVE-2021-35067 | HIGH | 8.1 | 0.9% | Oct 7, 2021 | Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who snif... |
| CVE-2021-33903 | HIGH | 8.8 | 1.1% | Oct 7, 2021 | In LCOS 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices, changing the password of the root user via the CL... |
| CVE-2021-40978 | HIGH | 7.5 | 14.5% | Oct 7, 2021 | The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obt... |
| CVE-2021-41770 | HIGH | 7.5 | 1.0% | Oct 7, 2021 | Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XM... |
| CVE-2021-42054 | HIGH | 7.5 | 1.1% | Oct 7, 2021 | ACCEL-PPP 1.12.0 has an out-of-bounds read in triton_context_schedule if the client exits after authentication. |
| CVE-2021-26557 | HIGH | 7.8 | 0.3% | Oct 7, 2021 | When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to a... |
| CVE-2021-26556 | HIGH | 7.8 | 0.3% | Oct 7, 2021 | When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an ... |
| CVE-2021-42040 | HIGH | 7.5 | 1.1% | Oct 6, 2021 | An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite l... |
| CVE-2021-41129 | HIGH | 8.1 | 1.7% | Oct 6, 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify ... |
| CVE-2021-34788 | HIGH | 7 | 0.2% | Oct 6, 2021 | A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS ... |
| CVE-2021-34780 | HIGH | 8.8 | 0.5% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34779 | HIGH | 8.8 | 0.5% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34766 | HIGH | 8.8 | 0.9% | Oct 6, 2021 | A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote... |
| CVE-2021-34748 | HIGH | 8.8 | 2.8% | Oct 6, 2021 | A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now