2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21681 | MEDIUM | 5.5 | 0.3% | Aug 31, 2021 | Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins ... |
| CVE-2021-21680 | HIGH | 7.1 | 1.3% | Aug 31, 2021 | Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) ... |
| CVE-2021-21679 | HIGH | 8.8 | 0.7% | Aug 31, 2021 | Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protecti... |
| CVE-2021-21678 | HIGH | 8.8 | 0.8% | Aug 31, 2021 | Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target... |
| CVE-2021-21677 | HIGH | 8.8 | 2.2% | Aug 31, 2021 | Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java obj... |
| CVE-2021-35222 | CRITICAL | 9.6 | 2.6% | Aug 31, 2021 | This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Executio... |
| CVE-2021-35221 | HIGH | 8.1 | 2.0% | Aug 31, 2021 | Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RC... |
| CVE-2021-39316 | HIGH | 7.5 | 66.5% | Aug 31, 2021 | The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-c... |
| CVE-2021-35220 | HIGH | 7.2 | 2.5% | Aug 31, 2021 | Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Sett... |
| CVE-2021-35219 | MEDIUM | 4.9 | 0.8% | Aug 31, 2021 | ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Set... |
| CVE-2021-3749 | HIGH | 7.5 | 8.5% | Aug 31, 2021 | axios is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-34581 | HIGH | 7.5 | 1.0% | Aug 31, 2021 | Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 75... |
| CVE-2021-34578 | HIGH | 8.1 | 1.0% | Aug 31, 2021 | This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by s... |
| CVE-2021-34565 | CRITICAL | 9.8 | 1.0% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. |
| CVE-2021-34564 | MEDIUM | 5.5 | 0.2% | Aug 31, 2021 | Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's crede... |
| CVE-2021-34563 | LOW | 3.3 | 0.2% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the coo... |
| CVE-2021-34562 | MEDIUM | 6.1 | 0.6% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's respons... |
| CVE-2021-34561 | HIGH | 8.8 | 0.9% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or ... |
| CVE-2021-34560 | MEDIUM | 5.5 | 0.2% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored cr... |
| CVE-2021-34559 | MEDIUM | 5.3 | 0.8% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in c... |
| CVE-2021-33555 | HIGH | 7.5 | 1.2% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal at... |
| CVE-2021-38145 | CRITICAL | 9.8 | 2.2% | Aug 31, 2021 | An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-p... |
| CVE-2021-38144 | MEDIUM | 5.4 | 0.9% | Aug 31, 2021 | An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a f... |
| CVE-2021-38143 | MEDIUM | 6.1 | 1.4% | Aug 31, 2021 | An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible f... |
| CVE-2021-40330 | HIGH | 7.5 | 3.2% | Aug 31, 2021 | git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may res... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now