2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24017 | MEDIUM | 4.3 | 0.5% | Sep 30, 2021 | An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign a... |
| CVE-2021-24016 | MEDIUM | 6.3 | 0.5% | Sep 30, 2021 | An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and... |
| CVE-2021-41109 | HIGH | 7.5 | 1.2% | Sep 30, 2021 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2021-21089 | LOW | 3.3 | 1.8% | Sep 30, 2021 | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e... |
| CVE-2021-41720 | — | — | — | Sep 30, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-41729 | CRITICAL | 9.1 | 1.0% | Sep 30, 2021 | BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrar... |
| CVE-2021-41302 | HIGH | 7.3 | 0.4% | Sep 30, 2021 | ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely... |
| CVE-2021-41301 | CRITICAL | 9.8 | 1.9% | Sep 30, 2021 | ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files... |
| CVE-2021-41300 | CRITICAL | 9.8 | 0.9% | Sep 30, 2021 | ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can... |
| CVE-2021-41299 | CRITICAL | 9.8 | 2.0% | Sep 30, 2021 | ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers c... |
| CVE-2021-41298 | HIGH | 8.8 | 0.8% | Sep 30, 2021 | ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct a... |
| CVE-2021-41297 | HIGH | 8.8 | 0.7% | Sep 30, 2021 | ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate priv... |
| CVE-2021-41296 | CRITICAL | 9.8 | 0.9% | Sep 30, 2021 | ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password at... |
| CVE-2021-41295 | HIGH | 8.8 | 0.4% | Sep 30, 2021 | ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a for... |
| CVE-2021-41294 | CRITICAL | 9.1 | 1.1% | Sep 30, 2021 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GE... |
| CVE-2021-41293 | HIGH | 7.5 | 20.1% | Sep 30, 2021 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific ... |
| CVE-2021-41292 | CRITICAL | 9.1 | 1.1% | Sep 30, 2021 | ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie pois... |
| CVE-2021-41291 | HIGH | 7.5 | 79.4% | Sep 30, 2021 | ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Mana... |
| CVE-2021-41290 | CRITICAL | 9.8 | 2.2% | Sep 30, 2021 | ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, un... |
| CVE-2021-41616 | CRITICAL | 9.8 | 3.2% | Sep 30, 2021 | Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL ... |
| CVE-2021-25963 | MEDIUM | 6.1 | 0.9% | Sep 30, 2021 | In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of ... |
| CVE-2021-41829 | HIGH | 7.5 | 3.1% | Sep 30, 2021 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain ... |
| CVE-2021-41828 | HIGH | 7.5 | 4.6% | Sep 30, 2021 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml. |
| CVE-2021-41827 | HIGH | 7.5 | 4.6% | Sep 30, 2021 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials ... |
| CVE-2021-41826 | MEDIUM | 6.1 | 11.9% | Sep 30, 2021 | PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now