2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22703 | HIGH | 7.5 | 0.6% | Feb 19, 2021 | A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/... |
| CVE-2021-22702 | HIGH | 7.5 | 0.6% | Feb 19, 2021 | A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/... |
| CVE-2021-26296 | HIGH | 7.5 | 3.0% | Feb 19, 2021 | In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, ... |
| CVE-2021-27405 | HIGH | 7.5 | 1.8% | Feb 19, 2021 | A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for N... |
| CVE-2021-26712 | HIGH | 7.5 | 3.6% | Feb 18, 2021 | Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk ... |
| CVE-2021-26717 | HIGH | 7.5 | 2.2% | Feb 18, 2021 | An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certifie... |
| CVE-2021-27379 | HIGH | 7.8 | 0.4% | Feb 18, 2021 | An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DM... |
| CVE-2021-23341 | HIGH | 7.5 | 3.2% | Feb 18, 2021 | The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc,... |
| CVE-2021-23340 | HIGH | 7.1 | 1.3% | Feb 18, 2021 | This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAct... |
| CVE-2021-20443 | HIGH | 8.8 | 0.8% | Feb 18, 2021 | IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is ou... |
| CVE-2021-20354 | HIGH | 7.5 | 3.7% | Feb 18, 2021 | IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker co... |
| CVE-2021-27138 | HIGH | 7.8 | 1.1% | Feb 17, 2021 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT. |
| CVE-2021-27097 | HIGH | 7.8 | 1.0% | Feb 17, 2021 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT. |
| CVE-2021-27374 | HIGH | 7.5 | 1.1% | Feb 17, 2021 | VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff ... |
| CVE-2021-26720 | HIGH | 7.8 | 0.4% | Feb 17, 2021 | avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-d... |
| CVE-2021-3396 | HIGH | 8.8 | 2.4% | Feb 17, 2021 | OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through... |
| CVE-2021-27367 | HIGH | 7.5 | 1.7% | Feb 17, 2021 | Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow D... |
| CVE-2021-26911 | HIGH | 7.4 | 1.1% | Feb 17, 2021 | core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode. |
| CVE-2021-1378 | HIGH | 7.5 | 1.5% | Feb 17, 2021 | A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker ... |
| CVE-2021-1366 | HIGH | 7.8 | 1.3% | Feb 17, 2021 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c... |
| CVE-2021-27224 | HIGH | 7.5 | 38.0% | Feb 17, 2021 | The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012e... |
| CVE-2021-25780 | HIGH | 7.2 | 2.5% | Feb 17, 2021 | An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could... |
| CVE-2021-22174 | HIGH | 7.5 | 2.7% | Feb 17, 2021 | Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture ... |
| CVE-2021-22173 | HIGH | 7.5 | 2.4% | Feb 17, 2021 | Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted ca... |
| CVE-2021-22854 | HIGH | 7.5 | 1.5% | Feb 17, 2021 | The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtai... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now