2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22524 | MEDIUM | 4.9 | 0.6% | Sep 13, 2021 | Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 |
| CVE-2021-40870 | CRITICAL | 9.8 | 92.4% | Sep 13, 2021 | An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous ... |
| CVE-2021-40867 | HIGH | 7.1 | 1.4% | Sep 13, 2021 | Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenti... |
| CVE-2021-40866 | HIGH | 8.8 | 1.7% | Sep 13, 2021 | Certain NETGEAR smart switches are affected by a remote admin password change by an unauthenticated attacker via the (di... |
| CVE-2021-23435 | MEDIUM | 6.1 | 0.7% | Sep 12, 2021 | This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value ... |
| CVE-2021-23440 | CRITICAL | 9.8 | 2.3% | Sep 12, 2021 | This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of... |
| CVE-2021-40146 | CRITICAL | 9.8 | 5.5% | Sep 11, 2021 | A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect A... |
| CVE-2021-38555 | CRITICAL | 9.1 | 2.7% | Sep 11, 2021 | An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to a... |
| CVE-2021-39207 | HIGH | 8.8 | 1.7% | Sep 10, 2021 | parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affec... |
| CVE-2021-24040 | CRITICAL | 9.8 | 17.4% | Sep 10, 2021 | Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files c... |
| CVE-2021-40864 | CRITICAL | 9.8 | 2.2% | Sep 10, 2021 | The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.d... |
| CVE-2021-40347 | MEDIUM | 5.4 | 1.1% | Sep 10, 2021 | An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) ca... |
| CVE-2021-3145 | MEDIUM | 6.7 | 0.5% | Sep 10, 2021 | In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication. |
| CVE-2021-3646 | MEDIUM | 6.1 | 0.7% | Sep 10, 2021 | btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-37422 | CRITICAL | 9.8 | 3.3% | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. |
| CVE-2021-37423 | CRITICAL | 9.8 | 2.7% | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. |
| CVE-2021-37418 | — | — | — | Sep 10, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-31874. Reason: This candidate is a reservation d... |
| CVE-2021-37414 | HIGH | 7.5 | 5.3% | Sep 10, 2021 | Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication. |
| CVE-2021-40373 | CRITICAL | 9.8 | 4.7% | Sep 10, 2021 | playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_con... |
| CVE-2021-38360 | CRITICAL | 9.8 | 2.2% | Sep 10, 2021 | The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in... |
| CVE-2021-38359 | MEDIUM | 6.1 | 0.8% | Sep 10, 2021 | The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Sit... |
| CVE-2021-38358 | MEDIUM | 6.1 | 0.8% | Sep 10, 2021 | The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/... |
| CVE-2021-38357 | MEDIUM | 6.1 | 0.8% | Sep 10, 2021 | The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/s... |
| CVE-2021-38355 | MEDIUM | 6.1 | 0.9% | Sep 10, 2021 | The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter fo... |
| CVE-2021-38354 | MEDIUM | 6.1 | 0.9% | Sep 10, 2021 | The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now