2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29415 | MEDIUM | 5.5 | 0.3% | May 21, 2021 | The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the... |
| CVE-2021-29414 | MEDIUM | 6.1 | 0.3% | May 21, 2021 | STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control. |
| CVE-2021-22409 | MEDIUM | 5.3 | 0.5% | May 20, 2021 | There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation o... |
| CVE-2021-22339 | MEDIUM | 6.5 | 0.3% | May 20, 2021 | There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient... |
| CVE-2021-27956 | MEDIUM | 6.1 | 1.6% | May 20, 2021 | Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user s... |
| CVE-2021-23386 | MEDIUM | 6.5 | 1.4% | May 20, 2021 | This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them befo... |
| CVE-2021-3313 | MEDIUM | 5.4 | 1.0% | May 20, 2021 | Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and th... |
| CVE-2021-32632 | MEDIUM | 4.3 | 0.6% | May 20, 2021 | Pajbot is a Twitch chat bot. Pajbot versions prior to 1.52 are vulnerable to cross-site request forgery (CSRF). Hosters ... |
| CVE-2021-29692 | MEDIUM | 5.9 | 1.0% | May 20, 2021 | IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure... |
| CVE-2021-29687 | MEDIUM | 5.3 | 1.3% | May 20, 2021 | IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses fr... |
| CVE-2021-29683 | MEDIUM | 6.5 | 0.5% | May 20, 2021 | IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated us... |
| CVE-2021-29682 | MEDIUM | 5.3 | 1.3% | May 20, 2021 | IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed techni... |
| CVE-2021-25933 | MEDIUM | 4.8 | 1.0% | May 20, 2021 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation... |
| CVE-2021-25929 | MEDIUM | 4.8 | 1.0% | May 20, 2021 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation... |
| CVE-2021-25930 | MEDIUM | 4.3 | 0.6% | May 20, 2021 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation... |
| CVE-2021-3536 | MEDIUM | 4.8 | 0.5% | May 20, 2021 | A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin conso... |
| CVE-2021-3426 | MEDIUM | 5.7 | 1.9% | May 20, 2021 | There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or a... |
| CVE-2021-29659 | MEDIUM | 6.5 | 1.3% | May 20, 2021 | ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in t... |
| CVE-2021-27467 | MEDIUM | 6.1 | 0.7% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s ... |
| CVE-2021-27465 | MEDIUM | 6.1 | 0.6% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applicatio... |
| CVE-2021-27463 | MEDIUM | 5.3 | 0.9% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applicatio... |
| CVE-2021-20719 | MEDIUM | 6.8 | 0.4% | May 20, 2021 | RFNTPS firmware versions System_01000004 and earlier, and Web_01000004 and earlier allow an attacker on the same network... |
| CVE-2021-29625 | MEDIUM | 6.1 | 9.6% | May 19, 2021 | Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4... |
| CVE-2021-29624 | MEDIUM | 6.5 | 0.8% | May 19, 2021 | fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fa... |
| CVE-2021-29622 | MEDIUM | 6.1 | 19.6% | May 19, 2021 | Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now