2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-3273HIGH7.2Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this v...
CVE-2021-21066HIGH7.8Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that ...
CVE-2021-21065HIGH7.8Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that ...
CVE-2021-1387HIGH8.6A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a ...
CVE-2021-1368HIGH8.8A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software coul...
CVE-2021-1230HIGH7.5A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centri...
CVE-2021-1227HIGH8.1A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct...
CVE-2021-21974HIGH8.8OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG...
CVE-2021-21617HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attack...
CVE-2021-20662HIGH7.5Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to al...
CVE-2021-20661HIGH8.1Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to d...
CVE-2021-20659HIGH8.8SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecifi...
CVE-2021-3410HIGH7.8A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may l...
CVE-2021-20194HIGH7.8There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_...
CVE-2021-20182HIGH8.8A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges us...
CVE-2021-26680HIGH7.2A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26679HIGH7.2A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26677HIGH7.8A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s):...
CVE-2021-26594HIGH8.8In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any contr...
CVE-2021-26593HIGH7.5In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they g...
CVE-2021-22882HIGH7.5UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may ca...
CVE-2021-22112HIGH8.8Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported ...
CVE-2021-20247HIGH7.4A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not ...
CVE-2021-27579HIGH7.8Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed ...
CVE-2021-26926HIGH7.1A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now