2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34408 | HIGH | 7.8 | 0.4% | Sep 27, 2021 | The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable direct... |
| CVE-2021-40108 | HIGH | 8.8 | 0.5% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on ... |
| CVE-2021-3828 | HIGH | 7.5 | 1.6% | Sep 27, 2021 | nltk is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3822 | HIGH | 7.5 | 1.4% | Sep 27, 2021 | jsoneditor is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3820 | HIGH | 7.5 | 1.2% | Sep 27, 2021 | inflect is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3819 | HIGH | 8.8 | 0.5% | Sep 27, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-23243 | HIGH | 7.8 | 0.1% | Sep 27, 2021 | In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be... |
| CVE-2021-40104 | HIGH | 7.5 | 1.3% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass. |
| CVE-2021-40103 | HIGH | 7.5 | 1.4% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF. |
| CVE-2021-40097 | HIGH | 8.8 | 2.4% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution vi... |
| CVE-2021-0612 | HIGH | 7.8 | 0.1% | Sep 27, 2021 | In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ... |
| CVE-2021-0611 | HIGH | 7.8 | 0.1% | Sep 27, 2021 | In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ... |
| CVE-2021-0610 | HIGH | 7.8 | 0.1% | Sep 27, 2021 | In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local ... |
| CVE-2021-34570 | HIGH | 7.5 | 0.9% | Sep 27, 2021 | Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through spe... |
| CVE-2021-40981 | HIGH | 7.3 | 0.4% | Sep 27, 2021 | ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the pu... |
| CVE-2021-31606 | HIGH | 7.5 | 2.4% | Sep 27, 2021 | furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients. |
| CVE-2021-31605 | HIGH | 7.5 | 3.3% | Sep 27, 2021 | furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This ca... |
| CVE-2021-34349 | HIGH | 7.2 | 1.5% | Sep 27, 2021 | A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ... |
| CVE-2021-41617 | HIGH | 7 | 2.4% | Sep 26, 2021 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio... |
| CVE-2021-40655 | HIGH | 7.5 | 87.0% | Sep 24, 2021 | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name... |
| CVE-2021-41504 | HIGH | 8 | 0.5% | Sep 24, 2021 | An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authen... |
| CVE-2021-41503 | HIGH | 8 | 0.4% | Sep 24, 2021 | DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authenticatio... |
| CVE-2021-2464 | HIGH | 7.8 | 0.3% | Sep 24, 2021 | Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitab... |
| CVE-2021-40309 | HIGH | 8.8 | 1.8% | Sep 24, 2021 | A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to ... |
| CVE-2021-28130 | HIGH | 7.8 | 0.4% | Sep 24, 2021 | Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload w... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now