2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29831 | HIGH | 8.1 | 1.4% | Sep 21, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Inje... |
| CVE-2021-29795 | MEDIUM | 6 | 0.2% | Sep 21, 2021 | IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of... |
| CVE-2021-41525 | MEDIUM | 5.5 | 0.2% | Sep 21, 2021 | An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNe... |
| CVE-2021-41531 | HIGH | 7.5 | 0.9% | Sep 21, 2021 | NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length... |
| CVE-2021-37741 | HIGH | 8.8 | 2.6% | Sep 21, 2021 | ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities. |
| CVE-2021-37424 | CRITICAL | 9.8 | 4.6% | Sep 21, 2021 | ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. |
| CVE-2021-37420 | MEDIUM | 6.5 | 1.9% | Sep 21, 2021 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. |
| CVE-2021-37419 | HIGH | 7.5 | 2.4% | Sep 21, 2021 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF. |
| CVE-2021-28960 | CRITICAL | 9.8 | 2.0% | Sep 21, 2021 | Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handlin... |
| CVE-2021-0869 | CRITICAL | 9.8 | 0.8% | Sep 21, 2021 | In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. ... |
| CVE-2021-31917 | CRITICAL | 9.8 | 1.3% | Sep 21, 2021 | A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An atta... |
| CVE-2021-26333 | MEDIUM | 5.5 | 0.5% | Sep 21, 2021 | An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionar... |
| CVE-2021-20829 | MEDIUM | 6.1 | 0.7% | Sep 21, 2021 | Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows r... |
| CVE-2021-20037 | HIGH | 7.8 | 0.4% | Sep 21, 2021 | SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads t... |
| CVE-2021-41083 | HIGH | 8.8 | 0.4% | Sep 20, 2021 | Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully ... |
| CVE-2021-39229 | HIGH | 7.5 | 1.8% | Sep 20, 2021 | Apprise is an open source library which allows you to send a notification to almost all of the most popular notification... |
| CVE-2021-41082 | HIGH | 7.5 | 1.7% | Sep 20, 2021 | Discourse is a platform for community discussion. In affected versions any private message that includes a group had its... |
| CVE-2021-34650 | MEDIUM | 6.1 | 0.8% | Sep 20, 2021 | The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/adm... |
| CVE-2021-39325 | MEDIUM | 6.1 | 0.9% | Sep 20, 2021 | The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation i... |
| CVE-2021-32838 | HIGH | 7.5 | 1.8% | Sep 20, 2021 | Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is... |
| CVE-2021-38899 | MEDIUM | 4.4 | 0.3% | Sep 20, 2021 | IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM ... |
| CVE-2021-32839 | HIGH | 7.5 | 2.1% | Sep 20, 2021 | sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expre... |
| CVE-2021-29856 | MEDIUM | 6.5 | 1.1% | Sep 20, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI M... |
| CVE-2021-29821 | MEDIUM | 5.4 | 0.5% | Sep 20, 2021 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vul... |
| CVE-2021-29820 | MEDIUM | 5.4 | 0.5% | Sep 20, 2021 | IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vul... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now