2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32172 | CRITICAL | 9.8 | 66.4% | Oct 7, 2021 | Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the... |
| CVE-2021-41770 | HIGH | 7.5 | 1.0% | Oct 7, 2021 | Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XM... |
| CVE-2021-42054 | HIGH | 7.5 | 1.1% | Oct 7, 2021 | ACCEL-PPP 1.12.0 has an out-of-bounds read in triton_context_schedule if the client exits after authentication. |
| CVE-2021-42053 | MEDIUM | 5.4 | 2.5% | Oct 7, 2021 | The Unicorn framework through 0.35.3 for Django allows XSS via component.name. |
| CVE-2021-26557 | HIGH | 7.8 | 0.3% | Oct 7, 2021 | When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to a... |
| CVE-2021-26556 | HIGH | 7.8 | 0.3% | Oct 7, 2021 | When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an ... |
| CVE-2021-21684 | MEDIUM | 6.1 | 1.2% | Oct 6, 2021 | Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications ... |
| CVE-2021-21683 | MEDIUM | 6.5 | 2.1% | Oct 6, 2021 | The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on ... |
| CVE-2021-21682 | MEDIUM | 4.3 | 1.0% | Oct 6, 2021 | Jenkins 2.314 and earlier, LTS 2.303.1 and earlier accepts names of jobs and other entities with a trailing dot characte... |
| CVE-2021-42044 | MEDIUM | 4.8 | 0.6% | Oct 6, 2021 | An issue was discovered in the Mentor dashboard in the GrowthExperiments extension in MediaWiki through 1.36.2. The Grow... |
| CVE-2021-42043 | MEDIUM | 6.1 | 0.7% | Oct 6, 2021 | An issue was discovered in Special:MediaSearch in the MediaSearch extension in MediaWiki through 1.36.2. The suggestion ... |
| CVE-2021-42042 | MEDIUM | 4.8 | 0.5% | Oct 6, 2021 | An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The g... |
| CVE-2021-42041 | MEDIUM | 6.1 | 1.0% | Oct 6, 2021 | An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being prope... |
| CVE-2021-42040 | HIGH | 7.5 | 1.1% | Oct 6, 2021 | An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite l... |
| CVE-2021-41129 | HIGH | 8.1 | 1.7% | Oct 6, 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify ... |
| CVE-2021-34788 | HIGH | 7 | 0.2% | Oct 6, 2021 | A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS ... |
| CVE-2021-34782 | MEDIUM | 4.3 | 0.8% | Oct 6, 2021 | A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access t... |
| CVE-2021-34780 | HIGH | 8.8 | 0.5% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34779 | HIGH | 8.8 | 0.5% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34778 | MEDIUM | 4.3 | 0.4% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34777 | MEDIUM | 4.3 | 0.4% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34776 | MEDIUM | 4.3 | 0.4% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34775 | MEDIUM | 4.3 | 0.4% | Oct 6, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S... |
| CVE-2021-34772 | MEDIUM | 6.1 | 0.9% | Oct 6, 2021 | A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker t... |
| CVE-2021-34766 | HIGH | 8.8 | 0.9% | Oct 6, 2021 | A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now