2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37794 | MEDIUM | 5.4 | 0.8% | Aug 31, 2021 | A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user auth... |
| CVE-2021-36234 | MEDIUM | 5.5 | 0.3% | Aug 31, 2021 | Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspeci... |
| CVE-2021-36233 | MEDIUM | 6.5 | 1.0% | Aug 31, 2021 | The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacke... |
| CVE-2021-36232 | HIGH | 8.8 | 1.1% | Aug 31, 2021 | Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate p... |
| CVE-2021-36231 | HIGH | 8.8 | 2.6% | Aug 31, 2021 | Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attacke... |
| CVE-2021-27668 | MEDIUM | 5.3 | 1.0% | Aug 31, 2021 | HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authenti... |
| CVE-2021-3634 | MEDIUM | 6.5 | 4.7% | Aug 31, 2021 | A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during th... |
| CVE-2021-39164 | LOW | 3.1 | 1.5% | Aug 31, 2021 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorise... |
| CVE-2021-39135 | HIGH | 7.8 | 0.6% | Aug 31, 2021 | `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the n... |
| CVE-2021-39134 | HIGH | 7.8 | 0.6% | Aug 31, 2021 | `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the... |
| CVE-2021-37713 | HIGH | 8.6 | 1.3% | Aug 31, 2021 | The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite ... |
| CVE-2021-37712 | HIGH | 8.6 | 1.8% | Aug 31, 2021 | The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite ... |
| CVE-2021-37701 | HIGH | 8.6 | 3.3% | Aug 31, 2021 | The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite a... |
| CVE-2021-35212 | HIGH | 8.8 | 1.6% | Aug 31, 2021 | An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A bli... |
| CVE-2021-22944 | HIGH | 8 | 0.4% | Aug 31, 2021 | A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role an... |
| CVE-2021-22943 | CRITICAL | 9.6 | 0.4% | Aug 31, 2021 | A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained ... |
| CVE-2021-22929 | MEDIUM | 6.1 | 0.4% | Aug 31, 2021 | An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that i... |
| CVE-2021-22684 | HIGH | 7.5 | 1.1% | Aug 31, 2021 | Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memo... |
| CVE-2021-21811 | CRITICAL | 9.8 | 1.1% | Aug 31, 2021 | A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A... |
| CVE-2021-39163 | LOW | 3.1 | 0.9% | Aug 31, 2021 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorise... |
| CVE-2021-35240 | MEDIUM | 4.8 | 1.1% | Aug 31, 2021 | A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they... |
| CVE-2021-35239 | MEDIUM | 5.4 | 1.0% | Aug 31, 2021 | A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink. |
| CVE-2021-35223 | HIGH | 8.8 | 2.9% | Aug 31, 2021 | The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command ... |
| CVE-2021-35213 | HIGH | 8.8 | 3.4% | Aug 31, 2021 | An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform versi... |
| CVE-2021-29907 | HIGH | 8.8 | 1.5% | Aug 31, 2021 | IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary co... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now