2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23428 | CRITICAL | 9.8 | 1.7% | Sep 1, 2021 | This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file p... |
| CVE-2021-23427 | CRITICAL | 9.8 | 1.4% | Sep 1, 2021 | This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to ... |
| CVE-2021-23426 | HIGH | 7.5 | 0.9% | Sep 1, 2021 | This affects all versions of package Proto. It is possible to inject pollute the object property of an application using... |
| CVE-2021-39170 | MEDIUM | 5.4 | 1.2% | Sep 1, 2021 | Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could ad... |
| CVE-2021-39166 | MEDIUM | 5.4 | 0.8% | Sep 1, 2021 | Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly ... |
| CVE-2021-35508 | HIGH | 8.8 | 1.5% | Sep 1, 2021 | NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges vi... |
| CVE-2021-40352 | MEDIUM | 6.5 | 9.7% | Sep 1, 2021 | OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can re... |
| CVE-2021-39379 | CRITICAL | 9.8 | 3.6% | Sep 1, 2021 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma... |
| CVE-2021-39378 | CRITICAL | 9.8 | 22.7% | Sep 1, 2021 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma... |
| CVE-2021-39377 | CRITICAL | 9.8 | 3.6% | Sep 1, 2021 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma... |
| CVE-2021-39373 | HIGH | 7.8 | 0.3% | Sep 1, 2021 | Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk manageme... |
| CVE-2021-37151 | MEDIUM | 5.3 | 0.9% | Sep 1, 2021 | CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is v... |
| CVE-2021-38703 | HIGH | 8.8 | 4.3% | Sep 1, 2021 | Wireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise u... |
| CVE-2021-35238 | MEDIUM | 4.8 | 1.1% | Sep 1, 2021 | User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website. |
| CVE-2021-39109 | HIGH | 7.5 | 1.7% | Sep 1, 2021 | The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary ... |
| CVE-2021-37415 | CRITICAL | 9.8 | 99.9% | Sep 1, 2021 | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs w... |
| CVE-2021-33582 | HIGH | 7.5 | 3.1% | Sep 1, 2021 | Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input tha... |
| CVE-2021-40353 | CRITICAL | 9.8 | 2.9% | Sep 1, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database... |
| CVE-2021-36235 | HIGH | 7.8 | 0.7% | Sep 1, 2021 | An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges c... |
| CVE-2021-22003 | HIGH | 7.5 | 1.0% | Aug 31, 2021 | VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious ac... |
| CVE-2021-22002 | CRITICAL | 9.8 | 1.2% | Aug 31, 2021 | VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be a... |
| CVE-2021-22029 | HIGH | 7.5 | 1.0% | Aug 31, 2021 | VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/syst... |
| CVE-2021-40085 | MEDIUM | 6.5 | 1.9% | Aug 31, 2021 | An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated at... |
| CVE-2021-39180 | HIGH | 8.8 | 2.4% | Aug 31, 2021 | OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.... |
| CVE-2021-39176 | HIGH | 7.5 | 1.9% | Aug 31, 2021 | detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now