2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-35213HIGH8.8An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform versi...
CVE-2021-29907HIGH8.8IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary co...
CVE-2021-21680HIGH7.1Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) ...
CVE-2021-21679HIGH8.8Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protecti...
CVE-2021-21678HIGH8.8Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target...
CVE-2021-21677HIGH8.8Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java obj...
CVE-2021-35221HIGH8.1Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RC...
CVE-2021-39316HIGH7.5The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-c...
CVE-2021-35220HIGH7.2Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Sett...
CVE-2021-3749HIGH7.5axios is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-34581HIGH7.5Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 75...
CVE-2021-34578HIGH8.1This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by s...
CVE-2021-34561HIGH8.8In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or ...
CVE-2021-33555HIGH7.5In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal at...
CVE-2021-40330HIGH7.5git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may res...
CVE-2021-36981HIGH8.8In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to e...
CVE-2021-27556HIGH7.2The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by ...
CVE-2021-32831HIGH7.2Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP'...
CVE-2021-39132HIGH8.8Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.1...
CVE-2021-36691HIGH7.5libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a m...
CVE-2021-35062HIGH8.1A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attac...
CVE-2021-38342HIGH8.1The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `np...
CVE-2021-36370HIGH7.5An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of t...
CVE-2021-29630HIGH8.1In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE...
CVE-2021-33019HIGH7.8A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by p...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now