2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1474 | HIGH | 8.6 | 0.7% | Apr 8, 2021 | Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could all... |
| CVE-2021-1386 | HIGH | 7.8 | 0.3% | Apr 8, 2021 | A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpo... |
| CVE-2021-1362 | HIGH | 8.8 | 2.7% | Apr 8, 2021 | A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager S... |
| CVE-2021-1309 | HIGH | 8.8 | 0.5% | Apr 8, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se... |
| CVE-2021-1308 | HIGH | 7.4 | 0.4% | Apr 8, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se... |
| CVE-2021-1251 | HIGH | 7.4 | 0.4% | Apr 8, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se... |
| CVE-2021-1137 | HIGH | 7.8 | 0.5% | Apr 8, 2021 | Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb... |
| CVE-2021-29641 | HIGH | 8.8 | 4.9% | Apr 7, 2021 | Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions incl... |
| CVE-2021-26758 | HIGH | 8.8 | 2.7% | Apr 7, 2021 | Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root term... |
| CVE-2021-30123 | HIGH | 8.8 | 3.4% | Apr 7, 2021 | FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code ... |
| CVE-2021-29627 | HIGH | 7.8 | 0.7% | Apr 7, 2021 | In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, liste... |
| CVE-2021-28927 | HIGH | 7.8 | 1.5% | Apr 7, 2021 | The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platfor... |
| CVE-2021-30185 | HIGH | 7.5 | 1.0% | Apr 7, 2021 | CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link. |
| CVE-2021-30184 | HIGH | 7.8 | 1.8% | Apr 7, 2021 | GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is relate... |
| CVE-2021-20692 | HIGH | 7.1 | 1.0% | Apr 7, 2021 | Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker ... |
| CVE-2021-20687 | HIGH | 8.8 | 0.6% | Apr 7, 2021 | Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of... |
| CVE-2021-1892 | HIGH | 7.8 | 0.2% | Apr 7, 2021 | Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Comput... |
| CVE-2021-30147 | HIGH | 8.8 | 3.5% | Apr 7, 2021 | DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php. |
| CVE-2021-27900 | HIGH | 8.1 | 2.5% | Apr 6, 2021 | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several... |
| CVE-2021-27899 | HIGH | 7.4 | 0.6% | Apr 6, 2021 | The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validati... |
| CVE-2021-22158 | HIGH | 7.2 | 0.6% | Apr 6, 2021 | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) i... |
| CVE-2021-21404 | HIGH | 7.5 | 2.0% | Apr 6, 2021 | Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv... |
| CVE-2021-21423 | HIGH | 8.1 | 1.4% | Apr 6, 2021 | `projen` is a project generation tool that synthesizes project configuration files such as `package.json`, `tsconfig.jso... |
| CVE-2021-24027 | HIGH | 7.5 | 3.8% | Apr 6, 2021 | A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may ha... |
| CVE-2021-20334 | HIGH | 7.8 | 0.2% | Apr 6, 2021 | A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now