2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20526 | MEDIUM | 5.3 | 1.1% | Oct 27, 2021 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t... |
| CVE-2021-38379 | MEDIUM | 5.5 | 0.2% | Oct 27, 2021 | The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. |
| CVE-2021-37221 | HIGH | 8.8 | 1.1% | Oct 27, 2021 | A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update ... |
| CVE-2021-36756 | MEDIUM | 6.5 | 0.4% | Oct 27, 2021 | CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. |
| CVE-2021-22101 | HIGH | 7.5 | 1.0% | Oct 27, 2021 | Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowi... |
| CVE-2021-41619 | HIGH | 7.2 | 2.6% | Oct 27, 2021 | An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the applicati... |
| CVE-2021-41590 | MEDIUM | 5.3 | 0.8% | Oct 27, 2021 | In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration ... |
| CVE-2021-41589 | CRITICAL | 9.8 | 2.3% | Oct 27, 2021 | In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and... |
| CVE-2021-41872 | HIGH | 7.5 | 1.2% | Oct 27, 2021 | Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by at... |
| CVE-2021-34580 | HIGH | 7.5 | 1.0% | Oct 27, 2021 | In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind o... |
| CVE-2021-38450 | HIGH | 8.8 | 1.0% | Oct 27, 2021 | The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft... |
| CVE-2021-37131 | MEDIUM | 6.8 | 0.6% | Oct 27, 2021 | There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high pri... |
| CVE-2021-37130 | HIGH | 7.5 | 0.8% | Oct 27, 2021 | There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses ex... |
| CVE-2021-37129 | HIGH | 7.5 | 0.7% | Oct 27, 2021 | There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a mo... |
| CVE-2021-37127 | HIGH | 7.2 | 0.7% | Oct 27, 2021 | There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the si... |
| CVE-2021-37124 | MEDIUM | 6.5 | 0.3% | Oct 27, 2021 | There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special char... |
| CVE-2021-37122 | MEDIUM | 6.5 | 0.3% | Oct 27, 2021 | There is a use-after-free (UAF) vulnerability in Huawei products. An attacker may craft specific packets to exploit this... |
| CVE-2021-35236 | MEDIUM | 5.3 | 0.5% | Oct 27, 2021 | The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tel... |
| CVE-2021-35235 | MEDIUM | 5.3 | 1.2% | Oct 27, 2021 | The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote... |
| CVE-2021-35233 | MEDIUM | 5.3 | 0.9% | Oct 27, 2021 | The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diag... |
| CVE-2021-32951 | MEDIUM | 5.3 | 0.9% | Oct 27, 2021 | WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unautho... |
| CVE-2021-26610 | HIGH | 8.8 | 0.4% | Oct 27, 2021 | The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upl... |
| CVE-2021-41866 | MEDIUM | 5.4 | 0.5% | Oct 26, 2021 | MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not... |
| CVE-2021-23877 | HIGH | 7.8 | 0.4% | Oct 26, 2021 | Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x ma... |
| CVE-2021-35499 | MEDIUM | 5.4 | 0.6% | Oct 26, 2021 | The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scriptin... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now