2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31355 | MEDIUM | 5.4 | 0.8% | Oct 19, 2021 | A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks... |
| CVE-2021-31354 | HIGH | 8.8 | 0.6% | Oct 19, 2021 | An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juni... |
| CVE-2021-31353 | HIGH | 7.5 | 1.1% | Oct 19, 2021 | An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an... |
| CVE-2021-31352 | MEDIUM | 5.3 | 0.8% | Oct 19, 2021 | An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the... |
| CVE-2021-31351 | HIGH | 7.5 | 1.0% | Oct 19, 2021 | An Improper Check for Unusual or Exceptional Conditions in packet processing on the MS-MPC/MS-MIC utilized by Juniper Ne... |
| CVE-2021-31350 | HIGH | 8.8 | 0.8% | Oct 19, 2021 | An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on... |
| CVE-2021-31349 | CRITICAL | 9.8 | 1.7% | Oct 19, 2021 | The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to v... |
| CVE-2021-0299 | HIGH | 7.5 | 1.0% | Oct 19, 2021 | An Improper Handling of Exceptional Conditions vulnerability in the processing of a transit or directly received malform... |
| CVE-2021-0298 | MEDIUM | 4.7 | 0.2% | Oct 19, 2021 | A Race Condition in the 'show chassis pic' command in Juniper Networks Junos OS Evolved may allow an attacker to crash t... |
| CVE-2021-0297 | MEDIUM | 6.5 | 0.7% | Oct 19, 2021 | A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP ... |
| CVE-2021-0296 | HIGH | 7.4 | 0.5% | Oct 19, 2021 | The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response... |
| CVE-2021-41149 | HIGH | 8.1 | 1.1% | Oct 19, 2021 | Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The t... |
| CVE-2021-41140 | MEDIUM | 5.3 | 0.9% | Oct 19, 2021 | Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affec... |
| CVE-2021-41131 | HIGH | 8.7 | 1.4% | Oct 19, 2021 | python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ng... |
| CVE-2021-35323 | MEDIUM | 6.1 | 5.6% | Oct 19, 2021 | Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login. |
| CVE-2021-32664 | MEDIUM | 4.8 | 0.8% | Oct 19, 2021 | Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability o... |
| CVE-2021-32663 | HIGH | 7.5 | 1.4% | Oct 19, 2021 | iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup ... |
| CVE-2021-33988 | MEDIUM | 6.1 | 1.0% | Oct 19, 2021 | Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious... |
| CVE-2021-38911 | MEDIUM | 4.9 | 0.5% | Oct 19, 2021 | IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenti... |
| CVE-2021-29912 | MEDIUM | 5.4 | 0.5% | Oct 19, 2021 | IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2021-3746 | MEDIUM | 6.5 | 0.9% | Oct 19, 2021 | A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is... |
| CVE-2021-39355 | MEDIUM | 4.8 | 1.0% | Oct 19, 2021 | The Indeed Job Importer WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validati... |
| CVE-2021-39343 | MEDIUM | 4.8 | 1.0% | Oct 19, 2021 | The MPL-Publisher WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and... |
| CVE-2021-39329 | MEDIUM | 4.8 | 1.0% | Oct 19, 2021 | The JobBoardWP WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sa... |
| CVE-2021-37137 | HIGH | 7.5 | 6.3% | Oct 19, 2021 | The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside thi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now