2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20372 | MEDIUM | 4.3 | 1.2% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another u... |
| CVE-2021-23447 | MEDIUM | 6.1 | 1.1% | Oct 7, 2021 | This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization whe... |
| CVE-2021-40439 | MEDIUM | 6.5 | 3.4% | Oct 7, 2021 | Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion L... |
| CVE-2021-3834 | MEDIUM | 6.1 | 0.6% | Oct 7, 2021 | Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker coul... |
| CVE-2021-37922 | MEDIUM | 5.3 | 2.2% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files fr... |
| CVE-2021-28661 | MEDIUM | 4.3 | 0.8% | Oct 7, 2021 | Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by que... |
| CVE-2021-41865 | MEDIUM | 6.5 | 1.0% | Oct 7, 2021 | HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to... |
| CVE-2021-36150 | MEDIUM | 6.1 | 0.8% | Oct 7, 2021 | SilverStripe Framework through 4.8.1 allows XSS. |
| CVE-2021-42053 | MEDIUM | 5.4 | 2.5% | Oct 7, 2021 | The Unicorn framework through 0.35.3 for Django allows XSS via component.name. |
| CVE-2021-21684 | MEDIUM | 6.1 | 1.2% | Oct 6, 2021 | Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications ... |
| CVE-2021-21683 | MEDIUM | 6.5 | 2.1% | Oct 6, 2021 | The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on ... |
| CVE-2021-21682 | MEDIUM | 4.3 | 1.0% | Oct 6, 2021 | Jenkins 2.314 and earlier, LTS 2.303.1 and earlier accepts names of jobs and other entities with a trailing dot characte... |
| CVE-2021-42044 | MEDIUM | 4.8 | 0.6% | Oct 6, 2021 | An issue was discovered in the Mentor dashboard in the GrowthExperiments extension in MediaWiki through 1.36.2. The Grow... |
| CVE-2021-42043 | MEDIUM | 6.1 | 0.7% | Oct 6, 2021 | An issue was discovered in Special:MediaSearch in the MediaSearch extension in MediaWiki through 1.36.2. The suggestion ... |
| CVE-2021-42042 | MEDIUM | 4.8 | 0.5% | Oct 6, 2021 | An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The g... |
| CVE-2021-42041 | MEDIUM | 6.1 | 1.0% | Oct 6, 2021 | An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being prope... |
| CVE-2021-34782 | MEDIUM | 4.3 | 0.8% | Oct 6, 2021 | A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access t... |
| CVE-2021-34778 | MEDIUM | 4.3 | 0.4% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34777 | MEDIUM | 4.3 | 0.4% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34776 | MEDIUM | 4.3 | 0.4% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34775 | MEDIUM | 4.3 | 0.4% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34772 | MEDIUM | 6.1 | 0.9% | Oct 6, 2021 | A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker t... |
| CVE-2021-34757 | MEDIUM | 5.5 | 0.6% | Oct 6, 2021 | Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator... |
| CVE-2021-34744 | MEDIUM | 4.9 | 0.7% | Oct 6, 2021 | Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator... |
| CVE-2021-34742 | MEDIUM | 6.1 | 0.8% | Oct 6, 2021 | A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenti... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now