2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32172CRITICAL9.8Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the...
CVE-2021-41770HIGH7.5Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XM...
CVE-2021-42054HIGH7.5ACCEL-PPP 1.12.0 has an out-of-bounds read in triton_context_schedule if the client exits after authentication.
CVE-2021-42053MEDIUM5.4The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
CVE-2021-26557HIGH7.8When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to a...
CVE-2021-26556HIGH7.8When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an ...
CVE-2021-21684MEDIUM6.1Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications ...
CVE-2021-21683MEDIUM6.5The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on ...
CVE-2021-21682MEDIUM4.3Jenkins 2.314 and earlier, LTS 2.303.1 and earlier accepts names of jobs and other entities with a trailing dot characte...
CVE-2021-42044MEDIUM4.8An issue was discovered in the Mentor dashboard in the GrowthExperiments extension in MediaWiki through 1.36.2. The Grow...
CVE-2021-42043MEDIUM6.1An issue was discovered in Special:MediaSearch in the MediaSearch extension in MediaWiki through 1.36.2. The suggestion ...
CVE-2021-42042MEDIUM4.8An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The g...
CVE-2021-42041MEDIUM6.1An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being prope...
CVE-2021-42040HIGH7.5An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite l...
CVE-2021-41129HIGH8.1Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify ...
CVE-2021-34788HIGH7A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS ...
CVE-2021-34782MEDIUM4.3A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access t...
CVE-2021-34780HIGH8.8Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S...
CVE-2021-34779HIGH8.8Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S...
CVE-2021-34778MEDIUM4.3Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S...
CVE-2021-34777MEDIUM4.3Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S...
CVE-2021-34776MEDIUM4.3Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S...
CVE-2021-34775MEDIUM4.3Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S...
CVE-2021-34772MEDIUM6.1A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker t...
CVE-2021-34766HIGH8.8A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now