2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43568 | CRITICAL | 9.8 | 1.0% | Nov 9, 2021 | The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non... |
| CVE-2021-43200 | CRITICAL | 9.8 | 1.1% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient. |
| CVE-2021-43193 | CRITICAL | 9.8 | 1.9% | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. |
| CVE-2021-43185 | CRITICAL | 9.8 | 1.9% | Nov 9, 2021 | JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. |
| CVE-2021-43183 | CRITICAL | 9.8 | 1.1% | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. |
| CVE-2021-43466 | CRITICAL | 9.8 | 3.9% | Nov 9, 2021 | In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to ... |
| CVE-2021-40358 | CRITICAL | 9.9 | 1.2% | Nov 9, 2021 | A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC... |
| CVE-2021-31890 | CRITICAL | 9.1 | 2.1% | Nov 9, 2021 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R... |
| CVE-2021-31889 | CRITICAL | 9.1 | 2.4% | Nov 9, 2021 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R... |
| CVE-2021-31886 | CRITICAL | 9.8 | 3.0% | Nov 9, 2021 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver... |
| CVE-2021-31884 | CRITICAL | 9.8 | 1.5% | Nov 9, 2021 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver... |
| CVE-2021-31346 | CRITICAL | 9.1 | 1.9% | Nov 9, 2021 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R... |
| CVE-2021-31345 | CRITICAL | 9.1 | 1.6% | Nov 9, 2021 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R... |
| CVE-2021-41170 | CRITICAL | 9.8 | 1.5% | Nov 8, 2021 | neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures d... |
| CVE-2021-24827 | CRITICAL | 9.8 | 12.9% | Nov 8, 2021 | The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic be... |
| CVE-2021-24731 | CRITICAL | 9.8 | 7.5% | Nov 8, 2021 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres... |
| CVE-2021-24693 | CRITICAL | 9 | 1.2% | Nov 8, 2021 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputti... |
| CVE-2021-28024 | CRITICAL | 9.8 | 1.3% | Nov 8, 2021 | Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to lo... |
| CVE-2021-28023 | CRITICAL | 9.8 | 1.3% | Nov 8, 2021 | Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious... |
| CVE-2021-25979 | CRITICAL | 9.8 | 1.1% | Nov 8, 2021 | Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or chang... |
| CVE-2021-30132 | CRITICAL | 9.8 | 1.1% | Nov 8, 2021 | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges. |
| CVE-2021-42371 | CRITICAL | 9.8 | 1.5% | Nov 8, 2021 | lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30. |
| CVE-2021-42077 | CRITICAL | 9.8 | 2.4% | Nov 8, 2021 | PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username... |
| CVE-2021-34684 | CRITICAL | 9.8 | 5.8% | Nov 8, 2021 | Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries o... |
| CVE-2021-42359 | CRITICAL | 9.1 | 3.9% | Nov 5, 2021 | WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a n... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now