2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21823 | HIGH | 7.5 | 0.9% | Aug 20, 2021 | An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 1... |
| CVE-2021-34433 | HIGH | 7.5 | 0.3% | Aug 20, 2021 | In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handsh... |
| CVE-2021-28490 | HIGH | 8.8 | 0.5% | Aug 19, 2021 | In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token. |
| CVE-2021-37698 | HIGH | 7.5 | 1.4% | Aug 19, 2021 | Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat... |
| CVE-2021-34645 | HIGH | 8.8 | 0.6% | Aug 19, 2021 | The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_s... |
| CVE-2021-31338 | HIGH | 7.8 | 0.2% | Aug 19, 2021 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to... |
| CVE-2021-24038 | HIGH | 7.8 | 0.2% | Aug 19, 2021 | Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle ... |
| CVE-2021-39273 | HIGH | 8.8 | 2.7% | Aug 19, 2021 | In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an u... |
| CVE-2021-36762 | HIGH | 7.5 | 2.3% | Aug 19, 2021 | An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing... |
| CVE-2021-31401 | HIGH | 7.5 | 2.3% | Aug 19, 2021 | An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't... |
| CVE-2021-27565 | HIGH | 7.5 | 2.6% | Aug 19, 2021 | The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loo... |
| CVE-2021-31400 | HIGH | 7.5 | 1.5% | Aug 19, 2021 | An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-... |
| CVE-2021-31228 | HIGH | 7.5 | 1.3% | Aug 19, 2021 | An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query'... |
| CVE-2021-31227 | HIGH | 7.5 | 1.7% | Aug 19, 2021 | An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parse... |
| CVE-2021-34749 | HIGH | 8.6 | 1.7% | Aug 18, 2021 | A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firep... |
| CVE-2021-34745 | HIGH | 7.8 | 0.2% | Aug 18, 2021 | A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local us... |
| CVE-2021-34716 | HIGH | 7.2 | 2.4% | Aug 18, 2021 | A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communicat... |
| CVE-2021-34715 | HIGH | 7.2 | 1.1% | Aug 18, 2021 | A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication... |
| CVE-2021-39270 | HIGH | 7.5 | 0.4% | Aug 18, 2021 | In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur. |
| CVE-2021-25218 | HIGH | 7.5 | 3.6% | Aug 18, 2021 | In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named ... |
| CVE-2021-37617 | HIGH | 7.3 | 0.5% | Aug 18, 2021 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop... |
| CVE-2021-39282 | HIGH | 7.5 | 1.5% | Aug 18, 2021 | Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files. |
| CVE-2021-23424 | HIGH | 7.5 | 2.0% | Aug 18, 2021 | This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing... |
| CVE-2021-37714 | HIGH | 7.5 | 6.9% | Aug 18, 2021 | jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML... |
| CVE-2021-37702 | HIGH | 8.8 | 1.1% | Aug 18, 2021 | Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now