2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37543 | HIGH | 8.8 | 1.4% | Aug 6, 2021 | In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects. |
| CVE-2021-36708 | HIGH | 7.5 | 1.2% | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the... |
| CVE-2021-37381 | HIGH | 8.8 | 0.6% | Aug 6, 2021 | Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos t... |
| CVE-2021-3580 | HIGH | 7.5 | 2.7% | Aug 5, 2021 | A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could us... |
| CVE-2021-37632 | HIGH | 8.1 | 1.7% | Aug 5, 2021 | SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn6... |
| CVE-2021-37156 | HIGH | 7.5 | 1.0% | Aug 5, 2021 | Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's ... |
| CVE-2021-35326 | HIGH | 7.5 | 2.5% | Aug 5, 2021 | A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configura... |
| CVE-2021-35325 | HIGH | 7.5 | 13.3% | Aug 5, 2021 | A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers... |
| CVE-2021-34639 | HIGH | 8.8 | 0.6% | Aug 5, 2021 | Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files w... |
| CVE-2021-34634 | HIGH | 8.8 | 0.7% | Aug 5, 2021 | The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function foun... |
| CVE-2021-34633 | HIGH | 8.8 | 0.7% | Aug 5, 2021 | The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in... |
| CVE-2021-28216 | HIGH | 7.8 | 0.4% | Aug 5, 2021 | BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3S... |
| CVE-2021-26586 | HIGH | 7.5 | 1.6% | Aug 5, 2021 | A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edg... |
| CVE-2021-22928 | HIGH | 7.8 | 0.2% | Aug 5, 2021 | A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Wind... |
| CVE-2021-22927 | HIGH | 8.1 | 0.8% | Aug 5, 2021 | A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provide... |
| CVE-2021-22926 | HIGH | 7.5 | 9.8% | Aug 5, 2021 | libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CU... |
| CVE-2021-22919 | HIGH | 7.5 | 0.9% | Aug 5, 2021 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known a... |
| CVE-2021-22517 | HIGH | 8.8 | 1.0% | Aug 5, 2021 | A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulne... |
| CVE-2021-21893 | HIGH | 8.8 | 1.9% | Aug 5, 2021 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.0.0.49893. A s... |
| CVE-2021-21870 | HIGH | 8.8 | 1.9% | Aug 5, 2021 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.4.37651. A s... |
| CVE-2021-21831 | HIGH | 8.8 | 4.5% | Aug 5, 2021 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A s... |
| CVE-2021-20592 | HIGH | 7.5 | 1.5% | Aug 5, 2021 | Missing synchronization vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.39... |
| CVE-2021-1630 | HIGH | 7.5 | 1.1% | Aug 5, 2021 | XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub,... |
| CVE-2021-3682 | HIGH | 8.5 | 2.9% | Aug 5, 2021 | A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping ... |
| CVE-2021-37614 | HIGH | 8.8 | 1.5% | Aug 5, 2021 | In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web appl... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now