2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35213 | HIGH | 8.8 | 3.4% | Aug 31, 2021 | An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform versi... |
| CVE-2021-29907 | HIGH | 8.8 | 1.5% | Aug 31, 2021 | IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary co... |
| CVE-2021-21680 | HIGH | 7.1 | 1.3% | Aug 31, 2021 | Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) ... |
| CVE-2021-21679 | HIGH | 8.8 | 0.7% | Aug 31, 2021 | Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protecti... |
| CVE-2021-21678 | HIGH | 8.8 | 0.8% | Aug 31, 2021 | Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target... |
| CVE-2021-21677 | HIGH | 8.8 | 2.2% | Aug 31, 2021 | Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java obj... |
| CVE-2021-35221 | HIGH | 8.1 | 2.0% | Aug 31, 2021 | Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RC... |
| CVE-2021-39316 | HIGH | 7.5 | 66.5% | Aug 31, 2021 | The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-c... |
| CVE-2021-35220 | HIGH | 7.2 | 2.5% | Aug 31, 2021 | Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Sett... |
| CVE-2021-3749 | HIGH | 7.5 | 8.5% | Aug 31, 2021 | axios is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-34581 | HIGH | 7.5 | 1.0% | Aug 31, 2021 | Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 75... |
| CVE-2021-34578 | HIGH | 8.1 | 1.0% | Aug 31, 2021 | This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by s... |
| CVE-2021-34561 | HIGH | 8.8 | 0.9% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or ... |
| CVE-2021-33555 | HIGH | 7.5 | 1.2% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal at... |
| CVE-2021-40330 | HIGH | 7.5 | 3.2% | Aug 31, 2021 | git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may res... |
| CVE-2021-36981 | HIGH | 8.8 | 6.0% | Aug 31, 2021 | In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to e... |
| CVE-2021-27556 | HIGH | 7.2 | 4.0% | Aug 31, 2021 | The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by ... |
| CVE-2021-32831 | HIGH | 7.2 | 1.5% | Aug 30, 2021 | Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP'... |
| CVE-2021-39132 | HIGH | 8.8 | 1.4% | Aug 30, 2021 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.1... |
| CVE-2021-36691 | HIGH | 7.5 | 1.1% | Aug 30, 2021 | libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a m... |
| CVE-2021-35062 | HIGH | 8.1 | 1.5% | Aug 30, 2021 | A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attac... |
| CVE-2021-38342 | HIGH | 8.1 | 0.5% | Aug 30, 2021 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `np... |
| CVE-2021-36370 | HIGH | 7.5 | 2.2% | Aug 30, 2021 | An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of t... |
| CVE-2021-29630 | HIGH | 8.1 | 1.6% | Aug 30, 2021 | In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE... |
| CVE-2021-33019 | HIGH | 7.8 | 2.4% | Aug 30, 2021 | A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by p... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now