2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37711 | HIGH | 8.8 | 1.1% | Aug 16, 2021 | Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Ver... |
| CVE-2021-36281 | HIGH | 8.8 | 0.7% | Aug 16, 2021 | Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privile... |
| CVE-2021-36279 | HIGH | 7.8 | 0.2% | Aug 16, 2021 | Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulner... |
| CVE-2021-32826 | HIGH | 8.1 | 1.1% | Aug 16, 2021 | Proxyee-Down is open source proxy software. An attacker being able to provide an extension script (eg: through a MiTM at... |
| CVE-2021-38608 | HIGH | 7.8 | 0.3% | Aug 16, 2021 | Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to ... |
| CVE-2021-21861 | HIGH | 8.8 | 1.6% | Aug 16, 2021 | An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A... |
| CVE-2021-21860 | HIGH | 8.8 | 1.6% | Aug 16, 2021 | An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A... |
| CVE-2021-21859 | HIGH | 8.8 | 1.6% | Aug 16, 2021 | An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A... |
| CVE-2021-37707 | HIGH | 7.5 | 0.9% | Aug 16, 2021 | Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulatio... |
| CVE-2021-22940 | HIGH | 7.5 | 14.0% | Aug 16, 2021 | Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to ... |
| CVE-2021-22938 | HIGH | 7.2 | 2.1% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje... |
| CVE-2021-22937 | HIGH | 7.2 | 7.8% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write... |
| CVE-2021-22935 | HIGH | 7.2 | 2.1% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje... |
| CVE-2021-22934 | HIGH | 7.2 | 4.7% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Co... |
| CVE-2021-22932 | HIGH | 7.5 | 0.4% | Aug 16, 2021 | An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes... |
| CVE-2021-38758 | HIGH | 7.5 | 2.3% | Aug 16, 2021 | Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.ph... |
| CVE-2021-35392 | HIGH | 7.5 | 83.2% | Aug 16, 2021 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP... |
| CVE-2021-33193 | HIGH | 7.5 | 46.2% | Aug 16, 2021 | A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request spl... |
| CVE-2021-23423 | HIGH | 7.5 | 1.1% | Aug 16, 2021 | This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include... |
| CVE-2021-23422 | HIGH | 7.8 | 0.8% | Aug 16, 2021 | This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Comma... |
| CVE-2021-3708 | HIGH | 7.8 | 24.6% | Aug 16, 2021 | D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticate... |
| CVE-2021-38712 | HIGH | 7.5 | 1.1% | Aug 16, 2021 | OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to bl... |
| CVE-2021-38711 | HIGH | 7.5 | 1.3% | Aug 16, 2021 | In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files. |
| CVE-2021-21815 | HIGH | 7.8 | 0.3% | Aug 13, 2021 | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs'... |
| CVE-2021-21814 | HIGH | 7.8 | 0.3% | Aug 13, 2021 | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the comman... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now