2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-37725HIGH8.1A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Ope...
CVE-2021-37724HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior t...
CVE-2021-37723HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior t...
CVE-2021-37722HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating...
CVE-2021-37721HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating...
CVE-2021-37720HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating...
CVE-2021-37719HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating...
CVE-2021-37718HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating...
CVE-2021-37717HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating...
CVE-2021-38617HIGH8.8In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to cre...
CVE-2021-38616HIGH8.8In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any l...
CVE-2021-38615HIGH8.1In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-i...
CVE-2021-37219HIGH8.8HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by...
CVE-2021-37218HIGH8.8HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same...
CVE-2021-36717HIGH7.5Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker ...
CVE-2021-36162HIGH8.8Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). Thes...
CVE-2021-28139HIGH8.8The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page up...
CVE-2021-39279HIGH8.8Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-100...
CVE-2021-38841HIGH8.8Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on th...
CVE-2021-33484HIGH7.5An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the in...
CVE-2021-24006HIGH8.8An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker wit...
CVE-2021-3770HIGH7.8vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-36744HIGH7.8Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an ...
CVE-2021-32568HIGH7.8mrdoc is vulnerable to Deserialization of Untrusted Data
CVE-2021-24395HIGH7.2The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now