2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35218 | HIGH | 8.8 | 76.4% | Sep 1, 2021 | Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized a... |
| CVE-2021-35216 | HIGH | 8.8 | 81.4% | Sep 1, 2021 | Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Pla... |
| CVE-2021-35215 | HIGH | 8.8 | 69.2% | Sep 1, 2021 | Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentic... |
| CVE-2021-23426 | HIGH | 7.5 | 0.9% | Sep 1, 2021 | This affects all versions of package Proto. It is possible to inject pollute the object property of an application using... |
| CVE-2021-35508 | HIGH | 8.8 | 1.5% | Sep 1, 2021 | NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges vi... |
| CVE-2021-39373 | HIGH | 7.8 | 0.3% | Sep 1, 2021 | Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk manageme... |
| CVE-2021-38703 | HIGH | 8.8 | 4.3% | Sep 1, 2021 | Wireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise u... |
| CVE-2021-39109 | HIGH | 7.5 | 1.7% | Sep 1, 2021 | The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary ... |
| CVE-2021-33582 | HIGH | 7.5 | 3.1% | Sep 1, 2021 | Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input tha... |
| CVE-2021-36235 | HIGH | 7.8 | 0.7% | Sep 1, 2021 | An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges c... |
| CVE-2021-22003 | HIGH | 7.5 | 1.0% | Aug 31, 2021 | VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious ac... |
| CVE-2021-22029 | HIGH | 7.5 | 1.0% | Aug 31, 2021 | VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/syst... |
| CVE-2021-39180 | HIGH | 8.8 | 2.4% | Aug 31, 2021 | OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.... |
| CVE-2021-39176 | HIGH | 7.5 | 1.9% | Aug 31, 2021 | detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 a... |
| CVE-2021-36232 | HIGH | 8.8 | 1.1% | Aug 31, 2021 | Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate p... |
| CVE-2021-36231 | HIGH | 8.8 | 2.6% | Aug 31, 2021 | Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attacke... |
| CVE-2021-39135 | HIGH | 7.8 | 0.6% | Aug 31, 2021 | `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the n... |
| CVE-2021-39134 | HIGH | 7.8 | 0.6% | Aug 31, 2021 | `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the... |
| CVE-2021-37713 | HIGH | 8.6 | 1.3% | Aug 31, 2021 | The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite ... |
| CVE-2021-37712 | HIGH | 8.6 | 1.8% | Aug 31, 2021 | The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite ... |
| CVE-2021-37701 | HIGH | 8.6 | 3.3% | Aug 31, 2021 | The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite a... |
| CVE-2021-35212 | HIGH | 8.8 | 1.6% | Aug 31, 2021 | An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A bli... |
| CVE-2021-22944 | HIGH | 8 | 0.4% | Aug 31, 2021 | A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role an... |
| CVE-2021-22684 | HIGH | 7.5 | 1.1% | Aug 31, 2021 | Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memo... |
| CVE-2021-35223 | HIGH | 8.8 | 2.9% | Aug 31, 2021 | The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now