2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21681MEDIUM5.5Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins ...
CVE-2021-21680HIGH7.1Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) ...
CVE-2021-21679HIGH8.8Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protecti...
CVE-2021-21678HIGH8.8Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target...
CVE-2021-21677HIGH8.8Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java obj...
CVE-2021-35222CRITICAL9.6This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Executio...
CVE-2021-35221HIGH8.1Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RC...
CVE-2021-39316HIGH7.5The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-c...
CVE-2021-35220HIGH7.2Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Sett...
CVE-2021-35219MEDIUM4.9ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Set...
CVE-2021-3749HIGH7.5axios is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-34581HIGH7.5Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 75...
CVE-2021-34578HIGH8.1This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by s...
CVE-2021-34565CRITICAL9.8In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.
CVE-2021-34564MEDIUM5.5Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's crede...
CVE-2021-34563LOW3.3In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the coo...
CVE-2021-34562MEDIUM6.1In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's respons...
CVE-2021-34561HIGH8.8In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or ...
CVE-2021-34560MEDIUM5.5In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored cr...
CVE-2021-34559MEDIUM5.3In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in c...
CVE-2021-33555HIGH7.5In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal at...
CVE-2021-38145CRITICAL9.8An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-p...
CVE-2021-38144MEDIUM5.4An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a f...
CVE-2021-38143MEDIUM6.1An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible f...
CVE-2021-40330HIGH7.5git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may res...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now