2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40999 | HIGH | 7.2 | 1.9% | Oct 15, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas... |
| CVE-2021-42340 | HIGH | 7.5 | 11.0% | Oct 14, 2021 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60... |
| CVE-2021-38295 | HIGH | 7.3 | 2.5% | Oct 14, 2021 | In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachmen... |
| CVE-2021-36389 | HIGH | 7.5 | 3.0% | Oct 14, 2021 | In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Ref... |
| CVE-2021-36388 | HIGH | 7.5 | 3.1% | Oct 14, 2021 | In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Obj... |
| CVE-2021-36387 | MEDIUM | 5.4 | 1.4% | Oct 14, 2021 | In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploita... |
| CVE-2021-42369 | HIGH | 8.8 | 1.0% | Oct 14, 2021 | Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject ... |
| CVE-2021-32571 | MEDIUM | 4.9 | 0.8% | Oct 14, 2021 | In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and p... |
| CVE-2021-42228 | HIGH | 8.8 | 1.0% | Oct 14, 2021 | A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.h... |
| CVE-2021-42227 | MEDIUM | 6.1 | 0.9% | Oct 14, 2021 | Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.htm... |
| CVE-2021-32569 | MEDIUM | 6.1 | 0.6% | Oct 14, 2021 | In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross... |
| CVE-2021-41142 | MEDIUM | 5.4 | 0.7% | Oct 14, 2021 | Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Ther... |
| CVE-2021-41132 | MEDIUM | 6.1 | 1.0% | Oct 14, 2021 | OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do ... |
| CVE-2021-39330 | — | — | — | Oct 14, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-24608. Reason: This candidate is a duplicate of ... |
| CVE-2021-38346 | HIGH | 8.8 | 1.7% | Oct 14, 2021 | The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a locati... |
| CVE-2021-38345 | MEDIUM | 6.5 | 0.7% | Oct 14, 2021 | The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in u... |
| CVE-2021-38344 | MEDIUM | 5.4 | 0.6% | Oct 14, 2021 | The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a s... |
| CVE-2021-37933 | HIGH | 7.5 | 1.5% | Oct 14, 2021 | An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, r... |
| CVE-2021-33179 | MEDIUM | 6.1 | 4.3% | Oct 14, 2021 | The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scri... |
| CVE-2021-33178 | MEDIUM | 6.5 | 1.8% | Oct 14, 2021 | The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path trave... |
| CVE-2021-33177 | HIGH | 8.8 | 9.8% | Oct 14, 2021 | The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation r... |
| CVE-2021-22964 | HIGH | 8.8 | 1.0% | Oct 14, 2021 | A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect... |
| CVE-2021-22963 | MEDIUM | 6.1 | 1.1% | Oct 14, 2021 | A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbit... |
| CVE-2021-20599 | HIGH | 7.5 | 1.3% | Oct 14, 2021 | Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC i... |
| CVE-2021-3882 | MEDIUM | 6.8 | 0.9% | Oct 14, 2021 | LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the Led... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now