2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37928 | CRITICAL | 9.8 | 9.2% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37926 | CRITICAL | 9.8 | 73.6% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37924 | CRITICAL | 9.8 | 10.6% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37923 | CRITICAL | 9.8 | 10.6% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37922 | MEDIUM | 5.3 | 2.2% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files fr... |
| CVE-2021-37921 | CRITICAL | 9.8 | 10.6% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37920 | CRITICAL | 9.8 | 10.6% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37919 | CRITICAL | 9.8 | 10.6% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37918 | CRITICAL | 9.8 | 73.6% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu... |
| CVE-2021-37762 | CRITICAL | 9.8 | 7.8% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execut... |
| CVE-2021-28129 | HIGH | 7.8 | 0.5% | Oct 7, 2021 | While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but ins... |
| CVE-2021-41794 | HIGH | 7.5 | 1.2% | Oct 7, 2021 | ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer... |
| CVE-2021-35067 | HIGH | 8.1 | 0.9% | Oct 7, 2021 | Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who snif... |
| CVE-2021-33903 | HIGH | 8.8 | 1.1% | Oct 7, 2021 | In LCOS 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices, changing the password of the root user via the CL... |
| CVE-2021-28661 | MEDIUM | 4.3 | 0.8% | Oct 7, 2021 | Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by que... |
| CVE-2021-41865 | MEDIUM | 6.5 | 1.0% | Oct 7, 2021 | HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to... |
| CVE-2021-40978 | HIGH | 7.5 | 14.5% | Oct 7, 2021 | The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obt... |
| CVE-2021-3832 | CRITICAL | 9.8 | 2.2% | Oct 7, 2021 | Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenti... |
| CVE-2021-36150 | MEDIUM | 6.1 | 0.8% | Oct 7, 2021 | SilverStripe Framework through 4.8.1 allows XSS. |
| CVE-2021-22958 | CRITICAL | 9.8 | 1.2% | Oct 7, 2021 | A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP ad... |
| CVE-2021-22930 | CRITICAL | 9.8 | 37.3% | Oct 7, 2021 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to ... |
| CVE-2021-20605 | — | — | — | Oct 7, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-20604 | — | — | — | Oct 7, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-20603 | — | — | — | Oct 7, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-20602 | — | — | — | Oct 7, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now