2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28901 | MEDIUM | 5.4 | 0.8% | Sep 15, 2021 | Multiple cross-site scripting (XSS) vulnerabilities exist in SITA Software Azur CMS 1.2.3.1 and earlier, which allows re... |
| CVE-2021-20433 | MEDIUM | 6.5 | 0.9% | Sep 15, 2021 | IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in fur... |
| CVE-2021-40238 | MEDIUM | 6.1 | 1.0% | Sep 15, 2021 | A Cross Site Scriptiong (XSS) vulnerability exists in the admin panel in Webuzo < 2.9.0 via an HTTP request to a non-exi... |
| CVE-2021-40156 | HIGH | 7.8 | 1.0% | Sep 15, 2021 | A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to write beyond allocated bou... |
| CVE-2021-40155 | HIGH | 7.8 | 1.0% | Sep 15, 2021 | A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boun... |
| CVE-2021-3795 | HIGH | 7.5 | 1.4% | Sep 15, 2021 | semver-regex is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-39392 | CRITICAL | 9.8 | 2.2% | Sep 15, 2021 | The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because ... |
| CVE-2021-39213 | HIGH | 8.8 | 1.0% | Sep 15, 2021 | GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with A... |
| CVE-2021-39211 | MEDIUM | 5.3 | 4.4% | Sep 15, 2021 | GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemet... |
| CVE-2021-39210 | MEDIUM | 6.5 | 1.0% | Sep 15, 2021 | GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autolo... |
| CVE-2021-37412 | MEDIUM | 6.1 | 1.1% | Sep 15, 2021 | The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar. |
| CVE-2021-27046 | HIGH | 7.8 | 0.3% | Sep 15, 2021 | A Memory Corruption vulnerability for PDF files in Autodesk Navisworks 2019, 2020, 2021, 2022 may lead to code execution... |
| CVE-2021-27045 | HIGH | 7.8 | 0.9% | Sep 15, 2021 | A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boun... |
| CVE-2021-39209 | HIGH | 8.8 | 0.5% | Sep 15, 2021 | GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can... |
| CVE-2021-40157 | HIGH | 7.8 | 0.7% | Sep 15, 2021 | A user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability... |
| CVE-2021-27044 | HIGH | 7.8 | 1.2% | Sep 15, 2021 | A Out-Of-Bounds Read/Write Vulnerability in Autodesk FBX Review version 1.4.0 may lead to remote code execution through ... |
| CVE-2021-39189 | MEDIUM | 5.3 | 1.2% | Sep 15, 2021 | Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerat... |
| CVE-2021-38156 | MEDIUM | 5.4 | 88.9% | Sep 15, 2021 | In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a ... |
| CVE-2021-21798 | HIGH | 7.8 | 15.6% | Sep 15, 2021 | An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. ... |
| CVE-2021-41076 | — | — | — | Sep 15, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-40845 | HIGH | 8.8 | 4.6% | Sep 15, 2021 | The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in... |
| CVE-2021-3801 | MEDIUM | 6.5 | 1.0% | Sep 15, 2021 | prism is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3797 | CRITICAL | 9.8 | 1.1% | Sep 15, 2021 | hestiacp is vulnerable to Use of Wrong Operator in String Comparison |
| CVE-2021-3796 | HIGH | 7.3 | 1.6% | Sep 15, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-3794 | HIGH | 7.5 | 1.2% | Sep 15, 2021 | vuelidate is vulnerable to Inefficient Regular Expression Complexity |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now