2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21086 | HIGH | 7.8 | 4.6% | Sep 2, 2021 | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e... |
| CVE-2021-33938 | HIGH | 7.5 | 1.3% | Sep 2, 2021 | Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers... |
| CVE-2021-33930 | HIGH | 7.5 | 1.4% | Sep 2, 2021 | Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows at... |
| CVE-2021-33929 | HIGH | 7.5 | 1.3% | Sep 2, 2021 | Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers... |
| CVE-2021-33928 | HIGH | 7.5 | 1.4% | Sep 2, 2021 | Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to ca... |
| CVE-2021-3758 | MEDIUM | 6.5 | 0.8% | Sep 2, 2021 | bookstack is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2021-3757 | CRITICAL | 9.8 | 1.6% | Sep 2, 2021 | immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-34765 | MEDIUM | 4.3 | 0.8% | Sep 2, 2021 | A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and downloa... |
| CVE-2021-34759 | MEDIUM | 4.8 | 0.6% | Sep 2, 2021 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au... |
| CVE-2021-34746 | CRITICAL | 9.8 | 17.7% | Sep 2, 2021 | A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infras... |
| CVE-2021-34733 | MEDIUM | 5.5 | 0.2% | Sep 2, 2021 | A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allo... |
| CVE-2021-34732 | MEDIUM | 6.1 | 0.8% | Sep 2, 2021 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent... |
| CVE-2021-31798 | MEDIUM | 4.4 | 0.4% | Sep 2, 2021 | The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and und... |
| CVE-2021-31796 | HIGH | 7.5 | 1.7% | Sep 2, 2021 | An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Di... |
| CVE-2021-31797 | MEDIUM | 5.1 | 0.3% | Sep 2, 2021 | The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race... |
| CVE-2021-39119 | MEDIUM | 5.3 | 0.8% | Sep 1, 2021 | Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving u... |
| CVE-2021-39115 | HIGH | 7.2 | 4.5% | Sep 1, 2021 | Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administ... |
| CVE-2021-40387 | HIGH | 8.8 | 2.4% | Sep 1, 2021 | An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is authenticat... |
| CVE-2021-40385 | HIGH | 8.8 | 1.1% | Sep 1, 2021 | An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege... |
| CVE-2021-39186 | MEDIUM | 6.1 | 1.0% | Sep 1, 2021 | GlobalNewFiles is a MediaWiki extension maintained by Miraheze. Prior to commit number cee254e1b158cdb0ddbea716b1d3edc31... |
| CVE-2021-39185 | CRITICAL | 9.1 | 0.6% | Sep 1, 2021 | Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0... |
| CVE-2021-39181 | HIGH | 8.8 | 1.9% | Sep 1, 2021 | OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared... |
| CVE-2021-30355 | HIGH | 8.6 | 6.9% | Sep 1, 2021 | Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user ... |
| CVE-2021-23438 | CRITICAL | 9.8 | 1.7% | Sep 1, 2021 | This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In p... |
| CVE-2021-40382 | HIGH | 7.5 | 22.7% | Sep 1, 2021 | An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now