2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42326 | MEDIUM | 5.3 | 1.1% | Oct 12, 2021 | Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient acc... |
| CVE-2021-39184 | HIGH | 8.6 | 1.0% | Oct 12, 2021 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability ... |
| CVE-2021-38915 | MEDIUM | 6.5 | 0.5% | Oct 12, 2021 | IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM ... |
| CVE-2021-38862 | HIGH | 7.5 | 0.7% | Oct 12, 2021 | IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to de... |
| CVE-2021-29645 | HIGH | 7.8 | 0.2% | Oct 12, 2021 | Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a ... |
| CVE-2021-29644 | CRITICAL | 9.8 | 2.5% | Oct 12, 2021 | Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Inte... |
| CVE-2021-40618 | CRITICAL | 9.8 | 1.4% | Oct 12, 2021 | An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_... |
| CVE-2021-40292 | MEDIUM | 5.4 | 0.5% | Oct 12, 2021 | A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter. |
| CVE-2021-3671 | MEDIUM | 6.5 | 2.0% | Oct 12, 2021 | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting... |
| CVE-2021-35496 | HIGH | 7.5 | 0.6% | Oct 12, 2021 | The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO Ja... |
| CVE-2021-35495 | HIGH | 8.8 | 0.8% | Oct 12, 2021 | The Scheduler Connection component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBC... |
| CVE-2021-35494 | MEDIUM | 5.3 | 0.5% | Oct 12, 2021 | The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperRepo... |
| CVE-2021-27003 | MEDIUM | 4.7 | 0.6% | Oct 12, 2021 | Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header whi... |
| CVE-2021-41797 | — | — | — | Oct 12, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2021-41796 | — | — | — | Oct 12, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2021-41071 | — | — | — | Oct 12, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2021-41070 | — | — | — | Oct 12, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2021-41136 | LOW | 3.7 | 1.1% | Oct 12, 2021 | Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior to versions 5.5.1 and 4.3.9, using `puma` with a proxy which... |
| CVE-2021-37735 | MEDIUM | 5.3 | 1.2% | Oct 12, 2021 | A remote denial of service vulnerability was discovered in Aruba Instant version(s): Aruba Instant 6.5.x.x: 6.5.4.18 and... |
| CVE-2021-37734 | MEDIUM | 6.5 | 0.9% | Oct 12, 2021 | A remote unauthorized read access to files vulnerability was discovered in Aruba Instant version(s): 6.4.x.x: 6.4.4.8-4.... |
| CVE-2021-37732 | HIGH | 7.2 | 3.0% | Oct 12, 2021 | A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6... |
| CVE-2021-35214 | MEDIUM | 4.7 | 1.8% | Oct 12, 2021 | The vulnerability in SolarWinds Pingdom can be described as a failure to invalidate user session upon password or email ... |
| CVE-2021-40500 | HIGH | 7.5 | 1.3% | Oct 12, 2021 | SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated atta... |
| CVE-2021-40499 | CRITICAL | 9.8 | 1.1% | Oct 12, 2021 | Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - vers... |
| CVE-2021-40498 | MEDIUM | 5.5 | 0.2% | Oct 12, 2021 | A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, whi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now