2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20124 | HIGH | 7.5 | 69.2% | Oct 13, 2021 | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the W... |
| CVE-2021-20123 | HIGH | 7.5 | 74.3% | Oct 13, 2021 | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the D... |
| CVE-2021-39304 | HIGH | 7.5 | 1.0% | Oct 13, 2021 | Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass. |
| CVE-2021-34814 | HIGH | 7.5 | 1.0% | Oct 13, 2021 | Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass. |
| CVE-2021-41137 | HIGH | 8.8 | 1.2% | Oct 13, 2021 | Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affe... |
| CVE-2021-33609 | MEDIUM | 4.3 | 0.9% | Oct 13, 2021 | Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through ... |
| CVE-2021-20834 | MEDIUM | 6.1 | 1.2% | Oct 13, 2021 | Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 an... |
| CVE-2021-20833 | HIGH | 7.4 | 0.5% | Oct 13, 2021 | The SNKRDUNK Market Place App for iOS versions prior to 2.2.0 does not verify server certificate properly, which allows ... |
| CVE-2021-20832 | MEDIUM | 5.3 | 0.8% | Oct 13, 2021 | InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerabi... |
| CVE-2021-20831 | HIGH | 8.8 | 0.7% | Oct 13, 2021 | Cross-site request forgery (CSRF) vulnerability in OG Tags versions prior to 2.0.2 allows a remote attacker to hijack th... |
| CVE-2021-20807 | MEDIUM | 6.1 | 0.7% | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote atta... |
| CVE-2021-20806 | MEDIUM | 6.1 | 0.8% | Oct 13, 2021 | Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitra... |
| CVE-2021-20805 | MEDIUM | 5.4 | 0.6% | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote auth... |
| CVE-2021-20804 | MEDIUM | 6.5 | 1.1% | Oct 13, 2021 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition... |
| CVE-2021-20803 | MEDIUM | 5.4 | 0.7% | Oct 13, 2021 | Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authentica... |
| CVE-2021-20802 | MEDIUM | 5.3 | 1.0% | Oct 13, 2021 | HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the inform... |
| CVE-2021-20801 | MEDIUM | 6.5 | 1.0% | Oct 13, 2021 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks... |
| CVE-2021-20800 | MEDIUM | 5.4 | 0.6% | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated... |
| CVE-2021-20799 | MEDIUM | 5.4 | 0.6% | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote auth... |
| CVE-2021-20798 | MEDIUM | 5.4 | 0.6% | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote auth... |
| CVE-2021-20797 | MEDIUM | 5.4 | 0.6% | Oct 13, 2021 | Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authen... |
| CVE-2021-20796 | MEDIUM | 6.5 | 1.5% | Oct 13, 2021 | Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated ... |
| CVE-2021-20795 | HIGH | 8.8 | 0.5% | Oct 13, 2021 | Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows ... |
| CVE-2021-41363 | MEDIUM | 4.2 | 0.4% | Oct 13, 2021 | Intune Management Extension Security Feature Bypass Vulnerability |
| CVE-2021-41361 | MEDIUM | 5.4 | 0.9% | Oct 13, 2021 | Active Directory Federation Server Spoofing Vulnerability |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now