2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34724 | MEDIUM | 6 | 0.3% | Sep 23, 2021 | A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileg... |
| CVE-2021-34723 | MEDIUM | 6.7 | 0.2% | Sep 23, 2021 | A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, loca... |
| CVE-2021-34712 | MEDIUM | 6.5 | 0.7% | Sep 23, 2021 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem... |
| CVE-2021-34705 | MEDIUM | 5.3 | 1.0% | Sep 23, 2021 | A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software c... |
| CVE-2021-34703 | MEDIUM | 6.5 | 1.1% | Sep 23, 2021 | A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Softwa... |
| CVE-2021-34696 | MEDIUM | 5.8 | 1.0% | Sep 23, 2021 | A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Ro... |
| CVE-2021-1625 | MEDIUM | 5.8 | 0.9% | Sep 23, 2021 | A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remot... |
| CVE-2021-1616 | MEDIUM | 4.7 | 1.2% | Sep 23, 2021 | A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Ci... |
| CVE-2021-1589 | MEDIUM | 6.5 | 0.9% | Sep 23, 2021 | A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote a... |
| CVE-2021-1546 | MEDIUM | 5.5 | 0.2% | Sep 23, 2021 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive inf... |
| CVE-2021-21992 | MEDIUM | 6.5 | 0.9% | Sep 22, 2021 | The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with... |
| CVE-2021-34648 | MEDIUM | 4.3 | 0.6% | Sep 22, 2021 | The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in... |
| CVE-2021-34647 | MEDIUM | 6.5 | 1.1% | Sep 22, 2021 | The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions funct... |
| CVE-2021-37860 | MEDIUM | 6.1 | 0.6% | Sep 22, 2021 | Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to ... |
| CVE-2021-39404 | MEDIUM | 4.8 | 0.5% | Sep 22, 2021 | MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database. |
| CVE-2021-39339 | MEDIUM | 5.3 | 1.3% | Sep 22, 2021 | The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file ... |
| CVE-2021-38153 | MEDIUM | 5.9 | 5.8% | Sep 22, 2021 | Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks... |
| CVE-2021-41087 | MEDIUM | 6.5 | 0.4% | Sep 21, 2021 | in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected v... |
| CVE-2021-41086 | MEDIUM | 5.4 | 1.0% | Sep 21, 2021 | jsuites is an open source collection of common required javascript web components. In affected versions users are subjec... |
| CVE-2021-41084 | MEDIUM | 4.7 | 1.2% | Sep 21, 2021 | http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or re... |
| CVE-2021-40868 | MEDIUM | 6.1 | 9.1% | Sep 21, 2021 | In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS. |
| CVE-2021-39230 | MEDIUM | 6.5 | 0.7% | Sep 21, 2021 | Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are re... |
| CVE-2021-23443 | MEDIUM | 6.1 | 0.9% | Sep 21, 2021 | This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization w... |
| CVE-2021-29795 | MEDIUM | 6 | 0.2% | Sep 21, 2021 | IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of... |
| CVE-2021-41525 | MEDIUM | 5.5 | 0.2% | Sep 21, 2021 | An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNe... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now