2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20377 | LOW | 2.7 | 0.9% | Sep 23, 2021 | IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error... |
| CVE-2021-41428 | — | — | — | Sep 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-41381 | HIGH | 7.5 | 52.9% | Sep 23, 2021 | Payara Micro Community 5.2021.6 and below allows Directory Traversal. |
| CVE-2021-3824 | MEDIUM | 6.1 | 0.7% | Sep 23, 2021 | OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web logi... |
| CVE-2021-36872 | MEDIUM | 5.4 | 0.6% | Sep 23, 2021 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3).... |
| CVE-2021-26750 | HIGH | 7.8 | 0.2% | Sep 23, 2021 | DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to... |
| CVE-2021-21913 | CRITICAL | 9.8 | 2.1% | Sep 23, 2021 | An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specia... |
| CVE-2021-32999 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Improper handling of exceptional conditions in SuiteLink server while processing command 0x01 |
| CVE-2021-32987 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Null pointer dereference in SuiteLink server while processing command 0x0b |
| CVE-2021-32979 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a |
| CVE-2021-32971 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Null pointer dereference in SuiteLink server while processing command 0x07 |
| CVE-2021-32963 | HIGH | 7.5 | 0.9% | Sep 23, 2021 | Null pointer dereference in SuiteLink server while processing commands 0x03/0x10 |
| CVE-2021-32959 | CRITICAL | 9.8 | 0.9% | Sep 23, 2021 | Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06 |
| CVE-2021-22953 | MEDIUM | 5.4 | 0.3% | Sep 23, 2021 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, an... |
| CVE-2021-22952 | HIGH | 8.8 | 1.0% | Sep 23, 2021 | A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained acc... |
| CVE-2021-22950 | MEDIUM | 6.5 | 0.4% | Sep 23, 2021 | Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be ... |
| CVE-2021-22949 | MEDIUM | 5.4 | 0.3% | Sep 23, 2021 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience,... |
| CVE-2021-22948 | HIGH | 7.1 | 2.6% | Sep 23, 2021 | Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqi... |
| CVE-2021-22945 | CRITICAL | 9.1 | 6.2% | Sep 23, 2021 | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer... |
| CVE-2021-22941 | CRITICAL | 9.8 | 53.6% | Sep 23, 2021 | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke... |
| CVE-2021-22020 | MEDIUM | 5.5 | 0.2% | Sep 23, 2021 | The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this ... |
| CVE-2021-22019 | HIGH | 7.5 | 1.6% | Sep 23, 2021 | The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with netw... |
| CVE-2021-22018 | MEDIUM | 6.5 | 1.1% | Sep 23, 2021 | The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A m... |
| CVE-2021-22017 | MEDIUM | 5.3 | 46.7% | Sep 23, 2021 | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A mali... |
| CVE-2021-22016 | MEDIUM | 6.1 | 0.9% | Sep 23, 2021 | The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attac... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now