2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33007 | HIGH | 7.8 | 1.1% | Aug 30, 2021 | A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a speciall... |
| CVE-2021-29631 | HIGH | 7.8 | 0.3% | Aug 30, 2021 | In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE... |
| CVE-2021-27020 | HIGH | 8.8 | 1.1% | Aug 30, 2021 | Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export. |
| CVE-2021-27018 | HIGH | 7.5 | 0.5% | Aug 30, 2021 | The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed b... |
| CVE-2021-22027 | HIGH | 7.5 | 1.2% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauth... |
| CVE-2021-22026 | HIGH | 7.5 | 1.1% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauth... |
| CVE-2021-22025 | HIGH | 7.5 | 0.8% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthe... |
| CVE-2021-22024 | HIGH | 7.5 | 1.0% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthentic... |
| CVE-2021-22023 | HIGH | 7.2 | 1.0% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor wi... |
| CVE-2021-29723 | HIGH | 7.5 | 0.9% | Aug 30, 2021 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou... |
| CVE-2021-29722 | HIGH | 7.5 | 0.9% | Aug 30, 2021 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou... |
| CVE-2021-37911 | HIGH | 8.8 | 0.6% | Aug 30, 2021 | The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attacke... |
| CVE-2021-24581 | HIGH | 8.8 | 4.1% | Aug 30, 2021 | The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting ... |
| CVE-2021-24580 | HIGH | 8.8 | 1.4% | Aug 30, 2021 | The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard ... |
| CVE-2021-24579 | HIGH | 8.8 | 8.2% | Aug 30, 2021 | The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unseria... |
| CVE-2021-25958 | HIGH | 7.5 | 2.6% | Aug 30, 2021 | In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations ... |
| CVE-2021-39113 | HIGH | 7.5 | 1.8% | Aug 30, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached c... |
| CVE-2021-39271 | HIGH | 8.8 | 3.7% | Aug 30, 2021 | OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attack... |
| CVE-2021-38385 | HIGH | 7.5 | 1.7% | Aug 30, 2021 | Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-s... |
| CVE-2021-36359 | HIGH | 8.8 | 4.0% | Aug 30, 2021 | OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via XML tag injection beca... |
| CVE-2021-40174 | HIGH | 8.8 | 1.0% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings. |
| CVE-2021-40173 | HIGH | 8.8 | 1.0% | Aug 29, 2021 | Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings. |
| CVE-2021-40172 | HIGH | 8.8 | 1.0% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings. |
| CVE-2021-38154 | HIGH | 7.5 | 4.0% | Aug 29, 2021 | Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server ... |
| CVE-2021-39174 | HIGH | 8.8 | 3.9% | Aug 28, 2021 | Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now