2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32807 | HIGH | 7.2 | 2.0% | Jul 30, 2021 | The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. R... |
| CVE-2021-27495 | HIGH | 7.1 | 0.8% | Jul 30, 2021 | Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All ... |
| CVE-2021-27491 | HIGH | 7.5 | 1.1% | Jul 30, 2021 | Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All ... |
| CVE-2021-35193 | HIGH | 7.5 | 1.2% | Jul 30, 2021 | Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across di... |
| CVE-2021-37601 | HIGH | 7.5 | 2.3% | Jul 30, 2021 | muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, me... |
| CVE-2021-36983 | HIGH | 7.8 | 0.5% | Jul 30, 2021 | replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/... |
| CVE-2021-36766 | HIGH | 7.2 | 3.7% | Jul 30, 2021 | Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/d... |
| CVE-2021-36754 | HIGH | 7.5 | 64.9% | Jul 30, 2021 | PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE ... |
| CVE-2021-36621 | HIGH | 8.1 | 2.1% | Jul 30, 2021 | Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is v... |
| CVE-2021-36386 | HIGH | 7.5 | 2.6% | Jul 30, 2021 | report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, w... |
| CVE-2021-36004 | HIGH | 8.8 | 2.2% | Jul 30, 2021 | Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. A... |
| CVE-2021-35472 | HIGH | 8.8 | 1.7% | Jul 30, 2021 | An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spo... |
| CVE-2021-34802 | HIGH | 8.8 | 1.0% | Jul 30, 2021 | A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow ... |
| CVE-2021-32610 | HIGH | 7.1 | 73.4% | Jul 30, 2021 | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability ... |
| CVE-2021-32558 | HIGH | 7.5 | 9.1% | Jul 30, 2021 | An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x befor... |
| CVE-2021-31799 | HIGH | 7 | 1.5% | Jul 30, 2021 | In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code ... |
| CVE-2021-28966 | HIGH | 7.5 | 58.0% | Jul 30, 2021 | In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter w... |
| CVE-2021-20783 | HIGH | 8.8 | 0.6% | Jul 30, 2021 | Cross-site request forgery (CSRF) vulnerability in Optical BB unit E-WMTA2.3 allows a remote attacker to hijack the auth... |
| CVE-2021-20114 | HIGH | 7.5 | 6.0% | Jul 30, 2021 | When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the ... |
| CVE-2021-29736 | HIGH | 8.8 | 1.1% | Jul 30, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the sys... |
| CVE-2021-36742 | HIGH | 7.8 | 1.5% | Jul 29, 2021 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free B... |
| CVE-2021-36741 | HIGH | 8.8 | 5.0% | Jul 29, 2021 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free... |
| CVE-2021-23415 | HIGH | 7.5 | 1.7% | Jul 28, 2021 | This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it... |
| CVE-2021-32000 | HIGH | 7.1 | 0.3% | Jul 28, 2021 | A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up i... |
| CVE-2021-34432 | HIGH | 7.5 | 1.2% | Jul 27, 2021 | In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now