2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21694 | CRITICAL | 9.8 | 1.5% | Nov 4, 2021 | FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check... |
| CVE-2021-21693 | CRITICAL | 9.8 | 1.5% | Nov 4, 2021 | When creating temporary files, agent-to-controller access to create those files is only checked after they've been creat... |
| CVE-2021-21692 | CRITICAL | 9.8 | 2.0% | Nov 4, 2021 | FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read'... |
| CVE-2021-21691 | CRITICAL | 9.8 | 2.0% | Nov 4, 2021 | Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318... |
| CVE-2021-21690 | CRITICAL | 9.8 | 2.5% | Nov 4, 2021 | Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path i... |
| CVE-2021-21689 | CRITICAL | 9.1 | 1.4% | Nov 4, 2021 | FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlie... |
| CVE-2021-21688 | HIGH | 7.5 | 1.3% | Nov 4, 2021 | The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earli... |
| CVE-2021-21687 | CRITICAL | 9.1 | 1.3% | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links wh... |
| CVE-2021-21686 | HIGH | 8.1 | 1.9% | Nov 4, 2021 | File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do... |
| CVE-2021-21685 | CRITICAL | 9.1 | 1.5% | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directorie... |
| CVE-2021-40128 | MEDIUM | 5.3 | 1.0% | Nov 4, 2021 | A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacke... |
| CVE-2021-40127 | MEDIUM | 5.3 | 1.2% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Bus... |
| CVE-2021-40126 | MEDIUM | 4.3 | 0.8% | Nov 4, 2021 | A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an... |
| CVE-2021-40124 | HIGH | 7.8 | 0.2% | Nov 4, 2021 | A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could ... |
| CVE-2021-40120 | HIGH | 7.2 | 1.9% | Nov 4, 2021 | A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an a... |
| CVE-2021-40119 | CRITICAL | 9.8 | 2.4% | Nov 4, 2021 | A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remo... |
| CVE-2021-40115 | MEDIUM | 6.1 | 0.8% | Nov 4, 2021 | A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site script... |
| CVE-2021-40113 | CRITICAL | 9.8 | 4.6% | Nov 4, 2021 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie... |
| CVE-2021-40112 | HIGH | 7.5 | 1.4% | Nov 4, 2021 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie... |
| CVE-2021-34795 | CRITICAL | 9.8 | 1.7% | Nov 4, 2021 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie... |
| CVE-2021-34784 | MEDIUM | 5.4 | 0.6% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable ... |
| CVE-2021-34774 | MEDIUM | 4.9 | 1.0% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an ... |
| CVE-2021-34773 | MEDIUM | 6.5 | 0.5% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie... |
| CVE-2021-34741 | HIGH | 7.5 | 1.2% | Nov 4, 2021 | A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could... |
| CVE-2021-34739 | HIGH | 8.1 | 1.6% | Nov 4, 2021 | A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an un... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now