2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-1132HIGH7.5A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NS...
CVE-2021-34753MEDIUM5.3A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Def...
CVE-2021-34752MEDIUM6.7A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative p...
CVE-2021-34751MEDIUM4.3A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Sof...
CVE-2021-34750MEDIUM4.3A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software ...
CVE-2021-1494MEDIUM5.8Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticate...
CVE-2021-1491MEDIUM6.5A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated...
CVE-2021-1484MEDIUM6.5A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to inj...
CVE-2021-1483MEDIUM6.4A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gai...
CVE-2021-1482MEDIUM6.4A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated...
CVE-2021-1481MEDIUM4.3A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated...
CVE-2021-1470MEDIUM4.9A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated...
CVE-2021-1466MEDIUM5.4A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacke...
CVE-2021-1464MEDIUM5A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorizat...
CVE-2021-3991MEDIUM4.3An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricte...
CVE-2021-3988MEDIUM6.1A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The...
CVE-2021-3987MEDIUM4.3An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without publi...
CVE-2021-3986MEDIUM4.3A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to othe...
CVE-2021-3902CRITICAL9.8An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Re...
CVE-2021-3841MEDIUM5.4sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through ...
CVE-2021-3838CRITICAL9.8DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passi...
CVE-2021-3742HIGH8.8A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to ...
CVE-2021-3741MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2...
CVE-2021-3740MEDIUM6.8A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidat...
CVE-2021-27704MEDIUM6.5Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now