2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37725 | HIGH | 8.1 | 0.4% | Sep 7, 2021 | A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Ope... |
| CVE-2021-37724 | HIGH | 7.2 | 3.0% | Sep 7, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior t... |
| CVE-2021-37723 | HIGH | 7.2 | 3.0% | Sep 7, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior t... |
| CVE-2021-37722 | HIGH | 7.2 | 3.0% | Sep 7, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating... |
| CVE-2021-37721 | HIGH | 7.2 | 3.0% | Sep 7, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating... |
| CVE-2021-37720 | HIGH | 7.2 | 3.0% | Sep 7, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating... |
| CVE-2021-37719 | HIGH | 7.2 | 2.8% | Sep 7, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating... |
| CVE-2021-37718 | HIGH | 7.2 | 3.0% | Sep 7, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating... |
| CVE-2021-37717 | HIGH | 7.2 | 3.0% | Sep 7, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating... |
| CVE-2021-38617 | HIGH | 8.8 | 1.4% | Sep 7, 2021 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to cre... |
| CVE-2021-38616 | HIGH | 8.8 | 1.3% | Sep 7, 2021 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any l... |
| CVE-2021-38615 | HIGH | 8.1 | 0.9% | Sep 7, 2021 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-i... |
| CVE-2021-37219 | HIGH | 8.8 | 1.2% | Sep 7, 2021 | HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by... |
| CVE-2021-37218 | HIGH | 8.8 | 0.7% | Sep 7, 2021 | HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same... |
| CVE-2021-36717 | HIGH | 7.5 | 0.9% | Sep 7, 2021 | Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker ... |
| CVE-2021-36162 | HIGH | 8.8 | 2.0% | Sep 7, 2021 | Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). Thes... |
| CVE-2021-28139 | HIGH | 8.8 | 1.3% | Sep 7, 2021 | The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page up... |
| CVE-2021-39279 | HIGH | 8.8 | 4.6% | Sep 7, 2021 | Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-100... |
| CVE-2021-38841 | HIGH | 8.8 | 3.8% | Sep 7, 2021 | Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on th... |
| CVE-2021-33484 | HIGH | 7.5 | 0.9% | Sep 7, 2021 | An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the in... |
| CVE-2021-24006 | HIGH | 8.8 | 0.9% | Sep 6, 2021 | An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker wit... |
| CVE-2021-3770 | HIGH | 7.8 | 0.7% | Sep 6, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-36744 | HIGH | 7.8 | 0.5% | Sep 6, 2021 | Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an ... |
| CVE-2021-32568 | HIGH | 7.8 | 0.8% | Sep 6, 2021 | mrdoc is vulnerable to Deserialization of Untrusted Data |
| CVE-2021-24395 | HIGH | 7.2 | 1.5% | Sep 6, 2021 | The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now