2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3830 | MEDIUM | 5.4 | 0.5% | Sep 26, 2021 | btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-21742 | MEDIUM | 5.5 | 0.6% | Sep 25, 2021 | There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter s... |
| CVE-2021-40655 | HIGH | 7.5 | 87.0% | Sep 24, 2021 | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name... |
| CVE-2021-40654 | MEDIUM | 6.5 | 1.8% | Sep 24, 2021 | An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by fo... |
| CVE-2021-41504 | HIGH | 8 | 0.5% | Sep 24, 2021 | An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authen... |
| CVE-2021-41503 | HIGH | 8 | 0.4% | Sep 24, 2021 | DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authenticatio... |
| CVE-2021-39246 | MEDIUM | 6.1 | 0.5% | Sep 24, 2021 | Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits... |
| CVE-2021-2464 | HIGH | 7.8 | 0.3% | Sep 24, 2021 | Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitab... |
| CVE-2021-35313 | — | — | — | Sep 24, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-22869 | CRITICAL | 9.8 | 1.2% | Sep 24, 2021 | An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted ... |
| CVE-2021-22868 | MEDIUM | 4.3 | 0.9% | Sep 24, 2021 | A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub... |
| CVE-2021-40310 | MEDIUM | 5.4 | 0.8% | Sep 24, 2021 | OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.ph... |
| CVE-2021-40309 | HIGH | 8.8 | 1.8% | Sep 24, 2021 | A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to ... |
| CVE-2021-28130 | HIGH | 7.8 | 0.4% | Sep 24, 2021 | Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload w... |
| CVE-2021-41588 | HIGH | 8.1 | 0.8% | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. Th... |
| CVE-2021-41587 | HIGH | 7.5 | 0.9% | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover cred... |
| CVE-2021-41586 | HIGH | 7.5 | 0.8% | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the sys... |
| CVE-2021-40102 | CRITICAL | 9.1 | 1.3% | Sep 24, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_... |
| CVE-2021-40100 | MEDIUM | 5.4 | 0.5% | Sep 24, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversatio... |
| CVE-2021-40099 | HIGH | 7.2 | 2.0% | Sep 24, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code ex... |
| CVE-2021-36749 | MEDIUM | 6.5 | 81.0% | Sep 24, 2021 | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In... |
| CVE-2021-41584 | HIGH | 7.5 | 1.3% | Sep 24, 2021 | Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensi... |
| CVE-2021-41583 | MEDIUM | 6.5 | 1.8% | Sep 24, 2021 | vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows r... |
| CVE-2021-41581 | MEDIUM | 5.5 | 0.6% | Sep 24, 2021 | x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buff... |
| CVE-2021-31923 | MEDIUM | 5.3 | 0.7% | Sep 24, 2021 | Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now