2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-41588HIGH8.1In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. Th...
CVE-2021-41587HIGH7.5In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover cred...
CVE-2021-41586HIGH7.5In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the sys...
CVE-2021-40099HIGH7.2An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code ex...
CVE-2021-41584HIGH7.5Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensi...
CVE-2021-41088HIGH8.8Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's ...
CVE-2021-38864HIGH7.5IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate valida...
CVE-2021-36823HIGH8.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Abso...
CVE-2021-41381HIGH7.5Payara Micro Community 5.2021.6 and below allows Directory Traversal.
CVE-2021-26750HIGH7.8DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to...
CVE-2021-32999HIGH7.5Improper handling of exceptional conditions in SuiteLink server while processing command 0x01
CVE-2021-32987HIGH7.5Null pointer dereference in SuiteLink server while processing command 0x0b
CVE-2021-32979HIGH7.5Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a
CVE-2021-32971HIGH7.5Null pointer dereference in SuiteLink server while processing command 0x07
CVE-2021-32963HIGH7.5Null pointer dereference in SuiteLink server while processing commands 0x03/0x10
CVE-2021-22952HIGH8.8A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained acc...
CVE-2021-22948HIGH7.1Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqi...
CVE-2021-22019HIGH7.5The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with netw...
CVE-2021-22015HIGH7.8The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and...
CVE-2021-22014HIGH7.2The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastr...
CVE-2021-22013HIGH7.5The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance manag...
CVE-2021-22012HIGH7.5The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. ...
CVE-2021-22010HIGH7.5The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to ...
CVE-2021-22009HIGH7.5The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor ...
CVE-2021-22008HIGH7.5The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor wit...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now