2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26698 | MEDIUM | 6.1 | 1.4% | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) w... |
| CVE-2021-26230 | MEDIUM | 6.1 | 0.9% | Jul 22, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke... |
| CVE-2021-26227 | MEDIUM | 6.1 | 0.9% | Jul 22, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke... |
| CVE-2021-34700 | MEDIUM | 5.5 | 0.3% | Jul 22, 2021 | A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to re... |
| CVE-2021-1617 | MEDIUM | 6.5 | 1.5% | Jul 22, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an auth... |
| CVE-2021-1614 | MEDIUM | 5.3 | 1.2% | Jul 22, 2021 | A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allo... |
| CVE-2021-1599 | MEDIUM | 5.4 | 0.8% | Jul 22, 2021 | A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authen... |
| CVE-2021-34431 | MEDIUM | 6.5 | 1.1% | Jul 22, 2021 | In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CO... |
| CVE-2021-29149 | MEDIUM | 6.2 | 0.2% | Jul 22, 2021 | A local bypass security restrictions vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Ser... |
| CVE-2021-29148 | MEDIUM | 6.1 | 0.6% | Jul 22, 2021 | A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Serie... |
| CVE-2021-35521 | MEDIUM | 5.9 | 1.4% | Jul 22, 2021 | A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows rem... |
| CVE-2021-35520 | MEDIUM | 6.2 | 0.3% | Jul 22, 2021 | A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows ph... |
| CVE-2021-30049 | MEDIUM | 6.1 | 2.5% | Jul 22, 2021 | SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI. |
| CVE-2021-1096 | MEDIUM | 5.5 | 0.3% | Jul 22, 2021 | NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) ha... |
| CVE-2021-1095 | MEDIUM | 5.5 | 0.4% | Jul 22, 2021 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler... |
| CVE-2021-1094 | MEDIUM | 6.1 | 0.4% | Jul 22, 2021 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler... |
| CVE-2021-1093 | MEDIUM | 5.5 | 0.4% | Jul 22, 2021 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert... |
| CVE-2021-37220 | MEDIUM | 5.5 | 1.3% | Jul 21, 2021 | MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximu... |
| CVE-2021-32775 | MEDIUM | 6.5 | 0.8% | Jul 21, 2021 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to m... |
| CVE-2021-32745 | MEDIUM | 6.1 | 0.6% | Jul 21, 2021 | Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online pri... |
| CVE-2021-23408 | MEDIUM | 4.3 | 1.4% | Jul 21, 2021 | This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser... |
| CVE-2021-21407 | MEDIUM | 6.5 | 0.5% | Jul 21, 2021 | Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation ... |
| CVE-2021-37159 | MEDIUM | 6.4 | 0.4% | Jul 21, 2021 | hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking... |
| CVE-2021-2445 | MEDIUM | 5.7 | 0.8% | Jul 21, 2021 | Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). Th... |
| CVE-2021-2444 | MEDIUM | 4.9 | 1.8% | Jul 21, 2021 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now