2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43350 | CRITICAL | 9.8 | 4.4% | Nov 11, 2021 | An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the P... |
| CVE-2021-26558 | HIGH | 7.5 | 2.4% | Nov 11, 2021 | Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link reso... |
| CVE-2021-25980 | HIGH | 8.8 | 1.2% | Nov 11, 2021 | In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 an... |
| CVE-2021-43397 | HIGH | 8.8 | 3.7% | Nov 11, 2021 | LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin. |
| CVE-2021-42847 | CRITICAL | 9.8 | 70.3% | Nov 11, 2021 | Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. |
| CVE-2021-42002 | CRITICAL | 9.8 | 7.2% | Nov 11, 2021 | Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code exec... |
| CVE-2021-41833 | CRITICAL | 9.8 | 7.8% | Nov 11, 2021 | Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. |
| CVE-2021-41081 | CRITICAL | 9.8 | 69.2% | Nov 11, 2021 | Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search... |
| CVE-2021-41080 | CRITICAL | 9.8 | 4.2% | Nov 11, 2021 | Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details sea... |
| CVE-2021-43573 | CRITICAL | 9.8 | 1.1% | Nov 11, 2021 | A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processin... |
| CVE-2021-40873 | HIGH | 7.5 | 1.3% | Nov 10, 2021 | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40.... |
| CVE-2021-40872 | HIGH | 7.5 | 1.5% | Nov 10, 2021 | An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a den... |
| CVE-2021-40871 | HIGH | 7.5 | 1.3% | Nov 10, 2021 | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial ... |
| CVE-2021-33816 | CRITICAL | 9.8 | 3.8% | Nov 10, 2021 | The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mecha... |
| CVE-2021-33618 | MEDIUM | 6.1 | 79.3% | Nov 10, 2021 | Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove at... |
| CVE-2021-42111 | MEDIUM | 5.5 | 0.2% | Nov 10, 2021 | An issue was discovered in the RCDevs OpenOTP app 1.4.13 and 1.4.14 for iOS. If it is installed on a jailbroken device, ... |
| CVE-2021-3572 | MEDIUM | 5.7 | 1.7% | Nov 10, 2021 | A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possi... |
| CVE-2021-32023 | HIGH | 7.8 | 0.3% | Nov 10, 2021 | An elevation of privilege vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574... |
| CVE-2021-32022 | MEDIUM | 5.5 | 0.3% | Nov 10, 2021 | A low privileged delete vulnerability using CEF RPC server of BlackBerry Protect for Windows version(s) versions 1574 an... |
| CVE-2021-32021 | HIGH | 7.8 | 0.3% | Nov 10, 2021 | A denial of service vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574 and e... |
| CVE-2021-22048 | HIGH | 8.8 | 10.0% | Nov 10, 2021 | The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authenti... |
| CVE-2021-41038 | MEDIUM | 6.1 | 0.7% | Nov 10, 2021 | In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via po... |
| CVE-2021-40520 | CRITICAL | 9.8 | 1.1% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials. |
| CVE-2021-40517 | MEDIUM | 5.4 | 0.5% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the ... |
| CVE-2021-3380 | MEDIUM | 6.5 | 1.3% | Nov 10, 2021 | Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive informati... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now