2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3273 | HIGH | 7.2 | 5.6% | Feb 25, 2021 | Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this v... |
| CVE-2021-21066 | HIGH | 7.8 | 3.4% | Feb 25, 2021 | Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that ... |
| CVE-2021-21065 | HIGH | 7.8 | 3.4% | Feb 25, 2021 | Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that ... |
| CVE-2021-1387 | HIGH | 8.6 | 1.4% | Feb 24, 2021 | A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a ... |
| CVE-2021-1368 | HIGH | 8.8 | 0.4% | Feb 24, 2021 | A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software coul... |
| CVE-2021-1230 | HIGH | 7.5 | 1.5% | Feb 24, 2021 | A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centri... |
| CVE-2021-1227 | HIGH | 8.1 | 0.7% | Feb 24, 2021 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct... |
| CVE-2021-21974 | HIGH | 8.8 | 45.1% | Feb 24, 2021 | OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG... |
| CVE-2021-21617 | HIGH | 8.8 | 0.9% | Feb 24, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attack... |
| CVE-2021-20662 | HIGH | 7.5 | 2.1% | Feb 24, 2021 | Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to al... |
| CVE-2021-20661 | HIGH | 8.1 | 2.4% | Feb 24, 2021 | Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to d... |
| CVE-2021-20659 | HIGH | 8.8 | 2.1% | Feb 24, 2021 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecifi... |
| CVE-2021-3410 | HIGH | 7.8 | 0.6% | Feb 23, 2021 | A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may l... |
| CVE-2021-20194 | HIGH | 7.8 | 0.4% | Feb 23, 2021 | There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_... |
| CVE-2021-20182 | HIGH | 8.8 | 1.1% | Feb 23, 2021 | A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges us... |
| CVE-2021-26680 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26679 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26677 | HIGH | 7.8 | 0.3% | Feb 23, 2021 | A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s):... |
| CVE-2021-26594 | HIGH | 8.8 | 1.2% | Feb 23, 2021 | In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any contr... |
| CVE-2021-26593 | HIGH | 7.5 | 1.4% | Feb 23, 2021 | In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they g... |
| CVE-2021-22882 | HIGH | 7.5 | 1.3% | Feb 23, 2021 | UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may ca... |
| CVE-2021-22112 | HIGH | 8.8 | 3.2% | Feb 23, 2021 | Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported ... |
| CVE-2021-20247 | HIGH | 7.4 | 1.9% | Feb 23, 2021 | A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not ... |
| CVE-2021-27579 | HIGH | 7.8 | 0.5% | Feb 23, 2021 | Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed ... |
| CVE-2021-26926 | HIGH | 7.1 | 1.2% | Feb 23, 2021 | A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now