2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42342 | CRITICAL | 9.8 | 59.5% | Oct 14, 2021 | An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passe... |
| CVE-2021-42341 | HIGH | 7.5 | 2.0% | Oct 14, 2021 | checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the... |
| CVE-2021-40854 | HIGH | 7.8 | 0.2% | Oct 14, 2021 | AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Cha... |
| CVE-2021-41075 | CRITICAL | 9.8 | 3.3% | Oct 13, 2021 | The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module AP... |
| CVE-2021-40493 | CRITICAL | 9.8 | 50.2% | Oct 13, 2021 | Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs ... |
| CVE-2021-26318 | MEDIUM | 4.7 | 0.3% | Oct 13, 2021 | A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially... |
| CVE-2021-42224 | CRITICAL | 9.8 | 2.2% | Oct 13, 2021 | SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php. |
| CVE-2021-42223 | MEDIUM | 6.1 | 0.8% | Oct 13, 2021 | Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php. |
| CVE-2021-40843 | HIGH | 7.3 | 0.4% | Oct 13, 2021 | Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An atta... |
| CVE-2021-40842 | CRITICAL | 9.8 | 1.0% | Oct 13, 2021 | Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability... |
| CVE-2021-20131 | HIGH | 8.8 | 16.0% | Oct 13, 2021 | ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope... |
| CVE-2021-20130 | HIGH | 8.8 | 31.6% | Oct 13, 2021 | ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope... |
| CVE-2021-41139 | MEDIUM | 6.1 | 1.0% | Oct 13, 2021 | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects ... |
| CVE-2021-40732 | MEDIUM | 6.1 | 2.3% | Oct 13, 2021 | XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in le... |
| CVE-2021-35498 | CRITICAL | 9.8 | 1.3% | Oct 13, 2021 | The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Servi... |
| CVE-2021-41138 | MEDIUM | 5.3 | 1.3% | Oct 13, 2021 | Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pa... |
| CVE-2021-3057 | HIGH | 8.1 | 1.4% | Oct 13, 2021 | A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the... |
| CVE-2021-22036 | MEDIUM | 6.5 | 0.9% | Oct 13, 2021 | VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. ... |
| CVE-2021-22035 | MEDIUM | 4.3 | 0.6% | Oct 13, 2021 | VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interact... |
| CVE-2021-22033 | LOW | 2.7 | 0.6% | Oct 13, 2021 | Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. |
| CVE-2021-20129 | HIGH | 7.5 | 1.6% | Oct 13, 2021 | An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to... |
| CVE-2021-20128 | MEDIUM | 5.4 | 0.6% | Oct 13, 2021 | The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable... |
| CVE-2021-20127 | HIGH | 8.1 | 1.1% | Oct 13, 2021 | An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek... |
| CVE-2021-20126 | HIGH | 8.8 | 0.6% | Oct 13, 2021 | Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a we... |
| CVE-2021-20125 | CRITICAL | 9.8 | 3.8% | Oct 13, 2021 | An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileSe... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now