2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41395 | MEDIUM | 6.5 | 0.8% | Sep 18, 2021 | Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations... |
| CVE-2021-41394 | MEDIUM | 5.3 | 1.2% | Sep 18, 2021 | Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts i... |
| CVE-2021-41393 | CRITICAL | 9.8 | 1.0% | Sep 18, 2021 | Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificate... |
| CVE-2021-3806 | MEDIUM | 5.3 | 0.7% | Sep 18, 2021 | A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same netw... |
| CVE-2021-41392 | CRITICAL | 9.8 | 2.7% | Sep 17, 2021 | static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafte... |
| CVE-2021-41391 | MEDIUM | 5.4 | 0.6% | Sep 17, 2021 | In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vul... |
| CVE-2021-41390 | HIGH | 8 | 1.1% | Sep 17, 2021 | In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is v... |
| CVE-2021-41387 | HIGH | 8.8 | 1.0% | Sep 17, 2021 | seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid ... |
| CVE-2021-39218 | MEDIUM | 6.3 | 0.3% | Sep 17, 2021 | Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is ... |
| CVE-2021-41383 | HIGH | 7.2 | 1.6% | Sep 17, 2021 | setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters... |
| CVE-2021-41380 | MEDIUM | 6.5 | 0.9% | Sep 17, 2021 | RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB proto... |
| CVE-2021-39219 | MEDIUM | 6.3 | 0.3% | Sep 17, 2021 | Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusio... |
| CVE-2021-39216 | MEDIUM | 6.3 | 0.3% | Sep 17, 2021 | Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 the... |
| CVE-2021-38412 | CRITICAL | 9.8 | 1.3% | Sep 17, 2021 | Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Ra... |
| CVE-2021-38406 | HIGH | 7.8 | 77.9% | Sep 17, 2021 | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specif... |
| CVE-2021-38404 | HIGH | 7.8 | 1.0% | Sep 17, 2021 | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specif... |
| CVE-2021-38402 | HIGH | 7.8 | 7.7% | Sep 17, 2021 | Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specif... |
| CVE-2021-41326 | CRITICAL | 9.8 | 2.0% | Sep 17, 2021 | In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call. |
| CVE-2021-40825 | HIGH | 8.6 | 1.1% | Sep 17, 2021 | nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. T... |
| CVE-2021-41317 | CRITICAL | 9.8 | 1.7% | Sep 17, 2021 | XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths. |
| CVE-2021-38304 | HIGH | 7.8 | 0.4% | Sep 17, 2021 | Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged ... |
| CVE-2021-41316 | HIGH | 8.1 | 1.4% | Sep 17, 2021 | The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (wit... |
| CVE-2021-41315 | HIGH | 8.8 | 1.2% | Sep 17, 2021 | The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows... |
| CVE-2021-39228 | CRITICAL | 9.8 | 1.3% | Sep 17, 2021 | Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. Th... |
| CVE-2021-39227 | CRITICAL | 9.8 | 1.3% | Sep 17, 2021 | ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge`... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now