2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30615 | MEDIUM | 6.5 | 5.3% | Sep 3, 2021 | Chromium: CVE-2021-30615 Cross-origin data leak in Navigation |
| CVE-2021-39193 | MEDIUM | 5.3 | 1.2% | Sep 3, 2021 | Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a... |
| CVE-2021-40492 | MEDIUM | 6.1 | 2.3% | Sep 3, 2021 | A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary... |
| CVE-2021-39191 | MEDIUM | 6.1 | 1.6% | Sep 3, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-40491 | MEDIUM | 6.5 | 0.9% | Sep 3, 2021 | The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they... |
| CVE-2021-38642 | MEDIUM | 6.1 | 1.1% | Sep 2, 2021 | Microsoft Edge for iOS Spoofing Vulnerability |
| CVE-2021-38641 | MEDIUM | 6.1 | 1.1% | Sep 2, 2021 | Microsoft Edge for Android Spoofing Vulnerability |
| CVE-2021-36930 | MEDIUM | 5.3 | 0.9% | Sep 2, 2021 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2021-26439 | MEDIUM | 4.6 | 2.5% | Sep 2, 2021 | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2021-26436 | MEDIUM | 6.1 | 2.3% | Sep 2, 2021 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2021-39322 | MEDIUM | 6.1 | 2.2% | Sep 2, 2021 | The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file.... |
| CVE-2021-38314 | MEDIUM | 5.3 | 27.6% | Sep 2, 2021 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions availabl... |
| CVE-2021-38312 | MEDIUM | 6.5 | 1.3% | Sep 2, 2021 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in... |
| CVE-2021-28559 | MEDIUM | 5.3 | 1.6% | Sep 2, 2021 | Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and e... |
| CVE-2021-28557 | MEDIUM | 4.3 | 1.7% | Sep 2, 2021 | Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and e... |
| CVE-2021-28555 | MEDIUM | 6.5 | 2.7% | Sep 2, 2021 | Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and e... |
| CVE-2021-27578 | MEDIUM | 6.1 | 3.0% | Sep 2, 2021 | Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scr... |
| CVE-2021-22791 | MEDIUM | 6.5 | 0.8% | Sep 2, 2021 | A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simula... |
| CVE-2021-22790 | MEDIUM | 6.5 | 0.8% | Sep 2, 2021 | A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulat... |
| CVE-2021-22789 | MEDIUM | 6.5 | 0.8% | Sep 2, 2021 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Deni... |
| CVE-2021-22525 | MEDIUM | 5.5 | 0.2% | Sep 2, 2021 | This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1 |
| CVE-2021-3758 | MEDIUM | 6.5 | 0.8% | Sep 2, 2021 | bookstack is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2021-34765 | MEDIUM | 4.3 | 0.8% | Sep 2, 2021 | A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and downloa... |
| CVE-2021-34759 | MEDIUM | 4.8 | 0.6% | Sep 2, 2021 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au... |
| CVE-2021-34733 | MEDIUM | 5.5 | 0.2% | Sep 2, 2021 | A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now