2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-42837CRITICAL9.8An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not c...
CVE-2021-35368CRITICAL9.8OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request ...
CVE-2021-42670CRITICAL9.8A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announ...
CVE-2021-42669CRITICAL9.8A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which all...
CVE-2021-42668CRITICAL9.8A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_cla...
CVE-2021-42667CRITICAL9.8A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-manag...
CVE-2021-42665CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of inde...
CVE-2021-42237CRITICAL9.8Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it...
CVE-2021-25508CRITICAL9.8Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abus...
CVE-2021-43400CRITICAL9.1An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-...
CVE-2021-21697CRITICAL9.1Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build director...
CVE-2021-21696CRITICAL9.8Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not limit agent read/write access to the libs/ directory inside ...
CVE-2021-21694CRITICAL9.8FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check...
CVE-2021-21693CRITICAL9.8When creating temporary files, agent-to-controller access to create those files is only checked after they've been creat...
CVE-2021-21692CRITICAL9.8FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read'...
CVE-2021-21691CRITICAL9.8Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318...
CVE-2021-21690CRITICAL9.8Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path i...
CVE-2021-21689CRITICAL9.1FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlie...
CVE-2021-21687CRITICAL9.1Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links wh...
CVE-2021-21685CRITICAL9.1Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directorie...
CVE-2021-40119CRITICAL9.8A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remo...
CVE-2021-40113CRITICAL9.8Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie...
CVE-2021-34795CRITICAL9.8Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie...
CVE-2021-42772CRITICAL9.8Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly...
CVE-2021-41492CRITICAL9.8Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Co...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now