2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42837 | CRITICAL | 9.8 | 1.2% | Nov 5, 2021 | An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not c... |
| CVE-2021-35368 | CRITICAL | 9.8 | 2.5% | Nov 5, 2021 | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request ... |
| CVE-2021-42670 | CRITICAL | 9.8 | 8.3% | Nov 5, 2021 | A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announ... |
| CVE-2021-42669 | CRITICAL | 9.8 | 23.3% | Nov 5, 2021 | A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which all... |
| CVE-2021-42668 | CRITICAL | 9.8 | 4.7% | Nov 5, 2021 | A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_cla... |
| CVE-2021-42667 | CRITICAL | 9.8 | 15.8% | Nov 5, 2021 | A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-manag... |
| CVE-2021-42665 | CRITICAL | 9.8 | 4.9% | Nov 5, 2021 | An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of inde... |
| CVE-2021-42237 | CRITICAL | 9.8 | 97.9% | Nov 5, 2021 | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it... |
| CVE-2021-25508 | CRITICAL | 9.8 | 0.8% | Nov 5, 2021 | Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abus... |
| CVE-2021-43400 | CRITICAL | 9.1 | 1.5% | Nov 4, 2021 | An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-... |
| CVE-2021-21697 | CRITICAL | 9.1 | 1.6% | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build director... |
| CVE-2021-21696 | CRITICAL | 9.8 | 2.3% | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not limit agent read/write access to the libs/ directory inside ... |
| CVE-2021-21694 | CRITICAL | 9.8 | 1.5% | Nov 4, 2021 | FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check... |
| CVE-2021-21693 | CRITICAL | 9.8 | 1.5% | Nov 4, 2021 | When creating temporary files, agent-to-controller access to create those files is only checked after they've been creat... |
| CVE-2021-21692 | CRITICAL | 9.8 | 2.0% | Nov 4, 2021 | FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read'... |
| CVE-2021-21691 | CRITICAL | 9.8 | 2.0% | Nov 4, 2021 | Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318... |
| CVE-2021-21690 | CRITICAL | 9.8 | 2.5% | Nov 4, 2021 | Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path i... |
| CVE-2021-21689 | CRITICAL | 9.1 | 1.4% | Nov 4, 2021 | FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlie... |
| CVE-2021-21687 | CRITICAL | 9.1 | 1.3% | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links wh... |
| CVE-2021-21685 | CRITICAL | 9.1 | 1.5% | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directorie... |
| CVE-2021-40119 | CRITICAL | 9.8 | 2.4% | Nov 4, 2021 | A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remo... |
| CVE-2021-40113 | CRITICAL | 9.8 | 4.6% | Nov 4, 2021 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie... |
| CVE-2021-34795 | CRITICAL | 9.8 | 1.7% | Nov 4, 2021 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie... |
| CVE-2021-42772 | CRITICAL | 9.8 | 1.2% | Nov 3, 2021 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly... |
| CVE-2021-41492 | CRITICAL | 9.8 | 1.6% | Nov 3, 2021 | Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Co... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now