2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39117 | MEDIUM | 4.8 | 0.6% | Aug 30, 2021 | The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers ... |
| CVE-2021-39111 | MEDIUM | 6.1 | 1.0% | Aug 30, 2021 | The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from ve... |
| CVE-2021-39272 | MEDIUM | 5.9 | 0.9% | Aug 30, 2021 | Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation ... |
| CVE-2021-40178 | MEDIUM | 6.1 | 0.8% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings. |
| CVE-2021-40176 | MEDIUM | 6.1 | 0.8% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5225 allows stored XSS. |
| CVE-2021-28700 | MEDIUM | 4.9 | 1.9% | Aug 27, 2021 | xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged... |
| CVE-2021-28699 | MEDIUM | 5.5 | 0.4% | Aug 27, 2021 | inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant ... |
| CVE-2021-28698 | MEDIUM | 5.5 | 0.3% | Aug 27, 2021 | long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the g... |
| CVE-2021-28696 | MEDIUM | 6.8 | 0.4% | Aug 27, 2021 | IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/... |
| CVE-2021-28695 | MEDIUM | 6.8 | 0.4% | Aug 27, 2021 | IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/... |
| CVE-2021-28694 | MEDIUM | 6.8 | 0.4% | Aug 27, 2021 | IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/... |
| CVE-2021-29744 | MEDIUM | 5.4 | 0.5% | Aug 27, 2021 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to em... |
| CVE-2021-39169 | MEDIUM | 5.4 | 0.7% | Aug 27, 2021 | Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the... |
| CVE-2021-39165 | MEDIUM | 6.5 | 9.8% | Aug 26, 2021 | Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in th... |
| CVE-2021-39161 | MEDIUM | 5.4 | 0.4% | Aug 26, 2021 | Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross... |
| CVE-2021-37715 | MEDIUM | 4.8 | 0.5% | Aug 26, 2021 | A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior ... |
| CVE-2021-29862 | MEDIUM | 5.5 | 0.2% | Aug 26, 2021 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to c... |
| CVE-2021-29727 | MEDIUM | 5.5 | 0.2% | Aug 26, 2021 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial o... |
| CVE-2021-36931 | MEDIUM | 4.4 | 1.2% | Aug 26, 2021 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2021-36929 | MEDIUM | 6.3 | 3.1% | Aug 26, 2021 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2021-36928 | MEDIUM | 6 | 0.7% | Aug 26, 2021 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2021-30597 | MEDIUM | 6.8 | 1.3% | Aug 26, 2021 | Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially ... |
| CVE-2021-30596 | MEDIUM | 4.3 | 1.7% | Aug 26, 2021 | Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoo... |
| CVE-2021-30594 | MEDIUM | 6.8 | 1.3% | Aug 26, 2021 | Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit ... |
| CVE-2021-32076 | MEDIUM | 5.3 | 1.2% | Aug 26, 2021 | Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now