2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29810 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting... |
| CVE-2021-38863 | MEDIUM | 5.5 | 0.2% | Sep 23, 2021 | IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authentica... |
| CVE-2021-36873 | MEDIUM | 5.4 | 1.2% | Sep 23, 2021 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.... |
| CVE-2021-29800 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Tivoli Netcool/OMNIbus_GUI and IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting... |
| CVE-2021-22276 | MEDIUM | 5.5 | 0.2% | Sep 23, 2021 | The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Acce... |
| CVE-2021-20563 | MEDIUM | 4.3 | 0.7% | Sep 23, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote authenciated user to obtain sensitive information... |
| CVE-2021-20485 | MEDIUM | 4.3 | 1.0% | Sep 23, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a d... |
| CVE-2021-20484 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-20435 | MEDIUM | 5.5 | 0.1% | Sep 23, 2021 | IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain... |
| CVE-2021-20434 | MEDIUM | 4.4 | 0.2% | Sep 23, 2021 | IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-... |
| CVE-2021-3824 | MEDIUM | 6.1 | 0.7% | Sep 23, 2021 | OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web logi... |
| CVE-2021-36872 | MEDIUM | 5.4 | 0.6% | Sep 23, 2021 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3).... |
| CVE-2021-22953 | MEDIUM | 5.4 | 0.3% | Sep 23, 2021 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, an... |
| CVE-2021-22950 | MEDIUM | 6.5 | 0.4% | Sep 23, 2021 | Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be ... |
| CVE-2021-22949 | MEDIUM | 5.4 | 0.3% | Sep 23, 2021 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience,... |
| CVE-2021-22020 | MEDIUM | 5.5 | 0.2% | Sep 23, 2021 | The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this ... |
| CVE-2021-22018 | MEDIUM | 6.5 | 1.1% | Sep 23, 2021 | The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A m... |
| CVE-2021-22017 | MEDIUM | 5.3 | 46.7% | Sep 23, 2021 | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A mali... |
| CVE-2021-22016 | MEDIUM | 6.1 | 0.9% | Sep 23, 2021 | The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attac... |
| CVE-2021-22011 | MEDIUM | 5.3 | 1.1% | Sep 23, 2021 | vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious act... |
| CVE-2021-22007 | MEDIUM | 5.5 | 0.2% | Sep 23, 2021 | The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user... |
| CVE-2021-21993 | MEDIUM | 6.5 | 0.9% | Sep 23, 2021 | The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vC... |
| CVE-2021-34729 | MEDIUM | 6.7 | 0.3% | Sep 23, 2021 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local... |
| CVE-2021-34726 | MEDIUM | 6.7 | 0.4% | Sep 23, 2021 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary com... |
| CVE-2021-34725 | MEDIUM | 6.7 | 0.3% | Sep 23, 2021 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now