2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32244 | MEDIUM | 5.4 | 0.9% | Jun 16, 2021 | Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Des... |
| CVE-2021-34204 | MEDIUM | 6.8 | 1.4% | Jun 16, 2021 | D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the devic... |
| CVE-2021-32659 | MEDIUM | 4.9 | 0.9% | Jun 16, 2021 | Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In version... |
| CVE-2021-1571 | MEDIUM | 6.1 | 9.7% | Jun 16, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a... |
| CVE-2021-1570 | MEDIUM | 6.5 | 0.8% | Jun 16, 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could ... |
| CVE-2021-1569 | MEDIUM | 6.5 | 0.8% | Jun 16, 2021 | Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could ... |
| CVE-2021-1568 | MEDIUM | 5.5 | 0.2% | Jun 16, 2021 | A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to c... |
| CVE-2021-1567 | MEDIUM | 6.7 | 0.2% | Jun 16, 2021 | A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authe... |
| CVE-2021-1543 | MEDIUM | 6.1 | 9.3% | Jun 16, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a... |
| CVE-2021-1524 | MEDIUM | 6.5 | 1.1% | Jun 16, 2021 | A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of se... |
| CVE-2021-1395 | MEDIUM | 6.1 | 0.8% | Jun 16, 2021 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate... |
| CVE-2021-20567 | MEDIUM | 4.4 | 0.1% | Jun 16, 2021 | IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or none... |
| CVE-2021-20488 | MEDIUM | 6.5 | 0.9% | Jun 16, 2021 | IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users i... |
| CVE-2021-20483 | MEDIUM | 6.5 | 0.9% | Jun 16, 2021 | IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted ... |
| CVE-2021-34801 | MEDIUM | 5.3 | 1.7% | Jun 16, 2021 | Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agen... |
| CVE-2021-21668 | MEDIUM | 5.4 | 76.0% | Jun 16, 2021 | Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS... |
| CVE-2021-21667 | MEDIUM | 5.4 | 75.7% | Jun 16, 2021 | Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in ... |
| CVE-2021-31857 | MEDIUM | 5.9 | 2.7% | Jun 16, 2021 | In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a brow... |
| CVE-2021-31159 | MEDIUM | 5.3 | 17.8% | Jun 16, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag... |
| CVE-2021-27479 | MEDIUM | 5.4 | 0.5% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to ... |
| CVE-2021-34683 | MEDIUM | 5.3 | 1.1% | Jun 16, 2021 | An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/... |
| CVE-2021-32033 | MEDIUM | 4.6 | 0.5% | Jun 16, 2021 | Protectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in cert... |
| CVE-2021-28979 | MEDIUM | 6.5 | 1.4% | Jun 16, 2021 | SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could ex... |
| CVE-2021-27487 | MEDIUM | 5.5 | 0.2% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could ... |
| CVE-2021-27481 | MEDIUM | 5.5 | 0.2% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange proce... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now