2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40684 | CRITICAL | 9.1 | 1.1% | Sep 22, 2021 | Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jo... |
| CVE-2021-37860 | MEDIUM | 6.1 | 0.6% | Sep 22, 2021 | Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to ... |
| CVE-2021-41011 | HIGH | 7.5 | 1.1% | Sep 22, 2021 | LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities un... |
| CVE-2021-40875 | HIGH | 7.5 | 48.4% | Sep 22, 2021 | Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac... |
| CVE-2021-37927 | CRITICAL | 9.8 | 2.2% | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. |
| CVE-2021-37925 | CRITICAL | 9.8 | 10.5% | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability. |
| CVE-2021-31847 | HIGH | 7.8 | 0.4% | Sep 22, 2021 | Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a lo... |
| CVE-2021-31841 | HIGH | 7.3 | 0.2% | Sep 22, 2021 | A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sid... |
| CVE-2021-31836 | HIGH | 7.1 | 0.2% | Sep 22, 2021 | Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user ... |
| CVE-2021-39404 | MEDIUM | 4.8 | 0.5% | Sep 22, 2021 | MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database. |
| CVE-2021-36260 | CRITICAL | 9.8 | 99.9% | Sep 22, 2021 | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,... |
| CVE-2021-3583 | HIGH | 7.1 | 0.9% | Sep 22, 2021 | A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through... |
| CVE-2021-39339 | MEDIUM | 5.3 | 1.3% | Sep 22, 2021 | The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file ... |
| CVE-2021-38153 | MEDIUM | 5.9 | 5.8% | Sep 22, 2021 | Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks... |
| CVE-2021-38112 | HIGH | 8.8 | 6.5% | Sep 22, 2021 | In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler... |
| CVE-2021-31819 | CRITICAL | 9.8 | 2.3% | Sep 22, 2021 | In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on sy... |
| CVE-2021-41382 | HIGH | 7.5 | 8.9% | Sep 22, 2021 | Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface. |
| CVE-2021-41087 | MEDIUM | 6.5 | 0.4% | Sep 21, 2021 | in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected v... |
| CVE-2021-41086 | MEDIUM | 5.4 | 1.0% | Sep 21, 2021 | jsuites is an open source collection of common required javascript web components. In affected versions users are subjec... |
| CVE-2021-41084 | MEDIUM | 4.7 | 1.2% | Sep 21, 2021 | http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or re... |
| CVE-2021-40847 | HIGH | 8.1 | 10.9% | Sep 21, 2021 | The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve ... |
| CVE-2021-40868 | MEDIUM | 6.1 | 9.1% | Sep 21, 2021 | In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS. |
| CVE-2021-39230 | MEDIUM | 6.5 | 0.7% | Sep 21, 2021 | Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are re... |
| CVE-2021-23444 | CRITICAL | 9.8 | 1.8% | Sep 21, 2021 | This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 whe... |
| CVE-2021-23443 | MEDIUM | 6.1 | 0.9% | Sep 21, 2021 | This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization w... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now