2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42093 | HIGH | 7.2 | 1.3% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manip... |
| CVE-2021-42092 | MEDIUM | 5.4 | 0.5% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to ... |
| CVE-2021-41130 | MEDIUM | 5.4 | 0.4% | Oct 7, 2021 | Extensible Service Proxy, a.k.a. ESP is a proxy which enables API management capabilities for JSON/REST or gRPC API serv... |
| CVE-2021-29700 | MEDIUM | 4.3 | 0.9% | Oct 7, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sen... |
| CVE-2021-20584 | HIGH | 7.5 | 1.3% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by imp... |
| CVE-2021-20571 | MEDIUM | 5.4 | 0.4% | Oct 7, 2021 | IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability all... |
| CVE-2021-20561 | MEDIUM | 6.1 | 0.6% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-20552 | MEDIUM | 4.3 | 1.0% | Oct 7, 2021 | IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a d... |
| CVE-2021-20489 | HIGH | 8.8 | 0.4% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attac... |
| CVE-2021-20481 | MEDIUM | 6.1 | 0.6% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-20473 | MEDIUM | 6.5 | 0.5% | Oct 7, 2021 | IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could al... |
| CVE-2021-20376 | MEDIUM | 4.3 | 0.7% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to th... |
| CVE-2021-20375 | MEDIUM | 6.5 | 0.8% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message s... |
| CVE-2021-20372 | MEDIUM | 4.3 | 1.2% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another u... |
| CVE-2021-42071 | CRITICAL | 9.8 | 69.9% | Oct 7, 2021 | In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac... |
| CVE-2021-23447 | MEDIUM | 6.1 | 1.1% | Oct 7, 2021 | This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization whe... |
| CVE-2021-42013 | CRITICAL | 9.8 | 100.0% | Oct 7, 2021 | It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path... |
| CVE-2021-40726 | HIGH | 7.8 | 5.1% | Oct 7, 2021 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a... |
| CVE-2021-40725 | HIGH | 7.8 | 5.1% | Oct 7, 2021 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a... |
| CVE-2021-40439 | MEDIUM | 6.5 | 3.4% | Oct 7, 2021 | Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion L... |
| CVE-2021-3834 | MEDIUM | 6.1 | 0.6% | Oct 7, 2021 | Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker coul... |
| CVE-2021-3833 | CRITICAL | 9.8 | 1.1% | Oct 7, 2021 | Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and... |
| CVE-2021-37931 | CRITICAL | 9.8 | 9.2% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37930 | CRITICAL | 9.8 | 9.2% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37929 | CRITICAL | 9.8 | 9.2% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now