2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41588 | HIGH | 8.1 | 0.8% | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. Th... |
| CVE-2021-41587 | HIGH | 7.5 | 0.9% | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover cred... |
| CVE-2021-41586 | HIGH | 7.5 | 0.8% | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the sys... |
| CVE-2021-40099 | HIGH | 7.2 | 2.0% | Sep 24, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code ex... |
| CVE-2021-41584 | HIGH | 7.5 | 1.3% | Sep 24, 2021 | Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensi... |
| CVE-2021-41088 | HIGH | 8.8 | 0.5% | Sep 23, 2021 | Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's ... |
| CVE-2021-38864 | HIGH | 7.5 | 0.7% | Sep 23, 2021 | IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate valida... |
| CVE-2021-36823 | HIGH | 8.2 | 0.7% | Sep 23, 2021 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Abso... |
| CVE-2021-41381 | HIGH | 7.5 | 52.9% | Sep 23, 2021 | Payara Micro Community 5.2021.6 and below allows Directory Traversal. |
| CVE-2021-26750 | HIGH | 7.8 | 0.2% | Sep 23, 2021 | DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to... |
| CVE-2021-32999 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Improper handling of exceptional conditions in SuiteLink server while processing command 0x01 |
| CVE-2021-32987 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Null pointer dereference in SuiteLink server while processing command 0x0b |
| CVE-2021-32979 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a |
| CVE-2021-32971 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Null pointer dereference in SuiteLink server while processing command 0x07 |
| CVE-2021-32963 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Null pointer dereference in SuiteLink server while processing commands 0x03/0x10 |
| CVE-2021-22952 | HIGH | 8.8 | 1.0% | Sep 23, 2021 | A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained acc... |
| CVE-2021-22948 | HIGH | 7.1 | 2.6% | Sep 23, 2021 | Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqi... |
| CVE-2021-22019 | HIGH | 7.5 | 1.6% | Sep 23, 2021 | The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with netw... |
| CVE-2021-22015 | HIGH | 7.8 | 1.8% | Sep 23, 2021 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and... |
| CVE-2021-22014 | HIGH | 7.2 | 1.5% | Sep 23, 2021 | The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastr... |
| CVE-2021-22013 | HIGH | 7.5 | 1.6% | Sep 23, 2021 | The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance manag... |
| CVE-2021-22012 | HIGH | 7.5 | 1.3% | Sep 23, 2021 | The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. ... |
| CVE-2021-22010 | HIGH | 7.5 | 1.6% | Sep 23, 2021 | The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to ... |
| CVE-2021-22009 | HIGH | 7.5 | 1.4% | Sep 23, 2021 | The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor ... |
| CVE-2021-22008 | HIGH | 7.5 | 1.6% | Sep 23, 2021 | The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor wit... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now