2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21086HIGH7.8Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e...
CVE-2021-33938HIGH7.5Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers...
CVE-2021-33930HIGH7.5Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows at...
CVE-2021-33929HIGH7.5Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers...
CVE-2021-33928HIGH7.5Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to ca...
CVE-2021-3758MEDIUM6.5bookstack is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2021-3757CRITICAL9.8immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-34765MEDIUM4.3A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and downloa...
CVE-2021-34759MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au...
CVE-2021-34746CRITICAL9.8A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infras...
CVE-2021-34733MEDIUM5.5A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allo...
CVE-2021-34732MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent...
CVE-2021-31798MEDIUM4.4The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and und...
CVE-2021-31796HIGH7.5An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Di...
CVE-2021-31797MEDIUM5.1The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race...
CVE-2021-39119MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving u...
CVE-2021-39115HIGH7.2Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administ...
CVE-2021-40387HIGH8.8An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is authenticat...
CVE-2021-40385HIGH8.8An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege...
CVE-2021-39186MEDIUM6.1GlobalNewFiles is a MediaWiki extension maintained by Miraheze. Prior to commit number cee254e1b158cdb0ddbea716b1d3edc31...
CVE-2021-39185CRITICAL9.1Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0...
CVE-2021-39181HIGH8.8OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared...
CVE-2021-30355HIGH8.6Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user ...
CVE-2021-23438CRITICAL9.8This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In p...
CVE-2021-40382HIGH7.5An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now