2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21666 | MEDIUM | 6.1 | 1.2% | Jun 10, 2021 | Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpo... |
| CVE-2021-21664 | MEDIUM | 6.5 | 1.0% | Jun 10, 2021 | An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Cre... |
| CVE-2021-21663 | MEDIUM | 4.3 | 1.0% | Jun 10, 2021 | A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read pe... |
| CVE-2021-21662 | MEDIUM | 4.3 | 0.9% | Jun 10, 2021 | A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read p... |
| CVE-2021-21661 | MEDIUM | 4.3 | 1.6% | Jun 10, 2021 | Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing ... |
| CVE-2021-31929 | MEDIUM | 4.3 | 0.5% | Jun 10, 2021 | Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and se... |
| CVE-2021-21735 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user... |
| CVE-2021-20293 | MEDIUM | 6.1 | 0.9% | Jun 10, 2021 | A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where i... |
| CVE-2021-30641 | MEDIUM | 5.3 | 52.3% | Jun 10, 2021 | Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' |
| CVE-2021-0134 | MEDIUM | 4.9 | 0.8% | Jun 9, 2021 | Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to ... |
| CVE-2021-0132 | MEDIUM | 4.9 | 0.8% | Jun 9, 2021 | Missing release of resource after effective lifetime in an API for the Intel(R) Security Library before version 3.3 may ... |
| CVE-2021-0131 | MEDIUM | 6.5 | 0.8% | Jun 9, 2021 | Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before v... |
| CVE-2021-0129 | MEDIUM | 5.7 | 0.8% | Jun 9, 2021 | Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjace... |
| CVE-2021-0089 | MEDIUM | 6.5 | 0.4% | Jun 9, 2021 | Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable informati... |
| CVE-2021-0086 | MEDIUM | 6.5 | 0.4% | Jun 9, 2021 | Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user t... |
| CVE-2021-0067 | MEDIUM | 6.7 | 0.2% | Jun 9, 2021 | Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enabl... |
| CVE-2021-0054 | MEDIUM | 6.7 | 0.2% | Jun 9, 2021 | Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable... |
| CVE-2021-0051 | MEDIUM | 4.4 | 0.2% | Jun 9, 2021 | Improper input validation in the Intel(R) SPS versions before SPS_E5_04.04.04.023.0, SPS_E5_04.04.03.228.0 or SPS_SoC-A_... |
| CVE-2021-0001 | MEDIUM | 4.7 | 0.2% | Jun 9, 2021 | Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enab... |
| CVE-2021-29049 | MEDIUM | 6.1 | 0.8% | Jun 9, 2021 | Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix... |
| CVE-2021-0113 | MEDIUM | 6.5 | 0.4% | Jun 9, 2021 | Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08... |
| CVE-2021-0097 | MEDIUM | 6.5 | 0.5% | Jun 9, 2021 | Path traversal in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may ... |
| CVE-2021-0095 | MEDIUM | 4.4 | 0.2% | Jun 9, 2021 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a... |
| CVE-2021-32942 | MEDIUM | 5.5 | 0.2% | Jun 9, 2021 | The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowVi... |
| CVE-2021-30133 | MEDIUM | 6.1 | 0.8% | Jun 9, 2021 | A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now