2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36981 | HIGH | 8.8 | 6.0% | Aug 31, 2021 | In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to e... |
| CVE-2021-36356 | CRITICAL | 9.8 | 54.4% | Aug 31, 2021 | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa... |
| CVE-2021-27558 | MEDIUM | 6.1 | 0.8% | Aug 31, 2021 | A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via... |
| CVE-2021-27557 | MEDIUM | 4.3 | 0.4% | Aug 31, 2021 | A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to upda... |
| CVE-2021-27556 | HIGH | 7.2 | 4.0% | Aug 31, 2021 | The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by ... |
| CVE-2021-39178 | MEDIUM | 6.1 | 1.1% | Aug 31, 2021 | Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability... |
| CVE-2021-39177 | CRITICAL | 9.8 | 1.4% | Aug 30, 2021 | Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNA... |
| CVE-2021-39175 | MEDIUM | 6.1 | 0.6% | Aug 30, 2021 | HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject a... |
| CVE-2021-36692 | MEDIUM | 6.5 | 1.2% | Aug 30, 2021 | libjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding... |
| CVE-2021-32832 | MEDIUM | 6.5 | 1.6% | Aug 30, 2021 | Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before ... |
| CVE-2021-32831 | HIGH | 7.2 | 1.5% | Aug 30, 2021 | Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP'... |
| CVE-2021-39133 | MEDIUM | 6.8 | 0.5% | Aug 30, 2021 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.1... |
| CVE-2021-39132 | HIGH | 8.8 | 1.4% | Aug 30, 2021 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.1... |
| CVE-2021-36691 | HIGH | 7.5 | 1.1% | Aug 30, 2021 | libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a m... |
| CVE-2021-35062 | HIGH | 8.1 | 1.5% | Aug 30, 2021 | A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attac... |
| CVE-2021-34434 | MEDIUM | 5.3 | 1.4% | Aug 30, 2021 | In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make... |
| CVE-2021-38343 | MEDIUM | 6.1 | 0.8% | Aug 30, 2021 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npB... |
| CVE-2021-38342 | HIGH | 8.1 | 0.5% | Aug 30, 2021 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `np... |
| CVE-2021-37421 | CRITICAL | 9.8 | 2.5% | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. |
| CVE-2021-37417 | CRITICAL | 9.8 | 4.8% | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. |
| CVE-2021-37416 | MEDIUM | 6.1 | 2.9% | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. |
| CVE-2021-36370 | HIGH | 7.5 | 2.2% | Aug 30, 2021 | An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of t... |
| CVE-2021-35061 | MEDIUM | 6.1 | 0.9% | Aug 30, 2021 | Multiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers... |
| CVE-2021-34668 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in... |
| CVE-2021-34646 | CRITICAL | 9.8 | 50.9% | Aug 30, 2021 | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication b... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now