2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23893 | HIGH | 7.8 | 0.1% | Oct 1, 2021 | Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow... |
| CVE-2021-3747 | HIGH | 7.8 | 0.2% | Oct 1, 2021 | The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with inc... |
| CVE-2021-3626 | HIGH | 8.8 | 0.2% | Oct 1, 2021 | The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket t... |
| CVE-2021-33626 | HIGH | 7.8 | 0.3% | Oct 1, 2021 | A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently ... |
| CVE-2021-29894 | HIGH | 7.5 | 0.7% | Sep 30, 2021 | IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorit... |
| CVE-2021-41109 | HIGH | 7.5 | 1.2% | Sep 30, 2021 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2021-41302 | HIGH | 7.3 | 0.4% | Sep 30, 2021 | ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely... |
| CVE-2021-41298 | HIGH | 8.8 | 0.8% | Sep 30, 2021 | ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct a... |
| CVE-2021-41297 | HIGH | 8.8 | 0.7% | Sep 30, 2021 | ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate priv... |
| CVE-2021-41295 | HIGH | 8.8 | 0.4% | Sep 30, 2021 | ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a for... |
| CVE-2021-41293 | HIGH | 7.5 | 20.1% | Sep 30, 2021 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific ... |
| CVE-2021-41291 | HIGH | 7.5 | 79.4% | Sep 30, 2021 | ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Mana... |
| CVE-2021-41829 | HIGH | 7.5 | 3.1% | Sep 30, 2021 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain ... |
| CVE-2021-41828 | HIGH | 7.5 | 4.6% | Sep 30, 2021 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml. |
| CVE-2021-41827 | HIGH | 7.5 | 4.6% | Sep 30, 2021 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials ... |
| CVE-2021-41824 | HIGH | 8.8 | 1.3% | Sep 30, 2021 | Craft CMS before 3.7.14 allows CSV injection. |
| CVE-2021-41034 | HIGH | 8.1 | 0.4% | Sep 29, 2021 | The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoin... |
| CVE-2021-41764 | HIGH | 8.8 | 0.7% | Sep 29, 2021 | A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does no... |
| CVE-2021-3653 | HIGH | 8.8 | 0.4% | Sep 29, 2021 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMC... |
| CVE-2021-39342 | HIGH | 7.5 | 0.7% | Sep 29, 2021 | The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaint... |
| CVE-2021-35945 | HIGH | 7.5 | 1.1% | Sep 29, 2021 | Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent f... |
| CVE-2021-35944 | HIGH | 7.5 | 1.1% | Sep 29, 2021 | Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent fr... |
| CVE-2021-22946 | HIGH | 7.5 | 4.2% | Sep 29, 2021 | A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FT... |
| CVE-2021-41732 | HIGH | 7.5 | 0.9% | Sep 29, 2021 | An issue was discovered in zeek version 4.1.0. There is a HTTP request splitting vulnerability that will invalidate any ... |
| CVE-2021-23446 | HIGH | 7.5 | 2.8% | Sep 29, 2021 | The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now