2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34415 | HIGH | 7.5 | 0.9% | Sep 27, 2021 | The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not... |
| CVE-2021-34414 | HIGH | 7.2 | 1.5% | Sep 27, 2021 | The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.202... |
| CVE-2021-34413 | HIGH | 7.5 | 0.6% | Sep 27, 2021 | All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-us... |
| CVE-2021-34412 | HIGH | 7.8 | 0.3% | Sep 27, 2021 | During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possibl... |
| CVE-2021-34411 | HIGH | 7.8 | 0.2% | Sep 27, 2021 | During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to lau... |
| CVE-2021-34410 | HIGH | 7.8 | 0.2% | Sep 27, 2021 | A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook... |
| CVE-2021-34409 | HIGH | 7.8 | 0.2% | Sep 27, 2021 | It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) i... |
| CVE-2021-34408 | HIGH | 7.8 | 0.4% | Sep 27, 2021 | The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable direct... |
| CVE-2021-33907 | CRITICAL | 9.8 | 3.0% | Sep 27, 2021 | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate informa... |
| CVE-2021-22272 | CRITICAL | 9.4 | 0.6% | Sep 27, 2021 | The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number i... |
| CVE-2021-40109 | MEDIUM | 6.4 | 0.5% | Sep 27, 2021 | A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A us... |
| CVE-2021-40108 | HIGH | 8.8 | 0.5% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on ... |
| CVE-2021-3828 | HIGH | 7.5 | 1.6% | Sep 27, 2021 | nltk is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3822 | HIGH | 7.5 | 1.4% | Sep 27, 2021 | jsoneditor is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3820 | HIGH | 7.5 | 1.2% | Sep 27, 2021 | inflect is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3819 | HIGH | 8.8 | 0.5% | Sep 27, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3818 | MEDIUM | 5.3 | 2.4% | Sep 27, 2021 | grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking |
| CVE-2021-3799 | MEDIUM | 5.4 | 1.5% | Sep 27, 2021 | grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames |
| CVE-2021-23243 | HIGH | 7.8 | 0.1% | Sep 27, 2021 | In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be... |
| CVE-2021-40106 | MEDIUM | 6.1 | 0.6% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the webs... |
| CVE-2021-40105 | MEDIUM | 6.1 | 0.6% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments. |
| CVE-2021-40104 | HIGH | 7.5 | 1.3% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass. |
| CVE-2021-40103 | HIGH | 7.5 | 1.4% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF. |
| CVE-2021-40098 | CRITICAL | 9.8 | 1.6% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regul... |
| CVE-2021-40097 | HIGH | 8.8 | 2.4% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution vi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now