2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34066 | CRITICAL | 9.8 | 2.0% | Aug 30, 2021 | An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability th... |
| CVE-2021-33055 | CRITICAL | 9.8 | 18.1% | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions. |
| CVE-2021-29630 | HIGH | 8.1 | 1.6% | Aug 30, 2021 | In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE... |
| CVE-2021-22021 | MEDIUM | 5.4 | 0.5% | Aug 30, 2021 | VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user ... |
| CVE-2021-3628 | MEDIUM | 5.4 | 0.9% | Aug 30, 2021 | OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attac... |
| CVE-2021-38393 | CRITICAL | 9.8 | 19.9% | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAE... |
| CVE-2021-38391 | CRITICAL | 9.8 | 3.5% | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnerg... |
| CVE-2021-38390 | CRITICAL | 9.8 | 19.8% | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAE... |
| CVE-2021-33019 | HIGH | 7.8 | 2.4% | Aug 30, 2021 | A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by p... |
| CVE-2021-33007 | HIGH | 7.8 | 1.1% | Aug 30, 2021 | A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a speciall... |
| CVE-2021-33003 | MEDIUM | 5.5 | 0.2% | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a w... |
| CVE-2021-32991 | MEDIUM | 4.3 | 0.4% | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an att... |
| CVE-2021-32983 | CRITICAL | 9.8 | 3.9% | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie... |
| CVE-2021-32967 | CRITICAL | 9.8 | 1.4% | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without bein... |
| CVE-2021-32955 | CRITICAL | 9.8 | 37.3% | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to re... |
| CVE-2021-29631 | HIGH | 7.8 | 0.3% | Aug 30, 2021 | In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE... |
| CVE-2021-27663 | CRITICAL | 9.8 | 1.7% | Aug 30, 2021 | A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access ... |
| CVE-2021-27020 | HIGH | 8.8 | 1.1% | Aug 30, 2021 | Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export. |
| CVE-2021-27019 | MEDIUM | 4.3 | 0.7% | Aug 30, 2021 | PuppetDB logging included potentially sensitive system information. |
| CVE-2021-27018 | HIGH | 7.5 | 0.5% | Aug 30, 2021 | The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed b... |
| CVE-2021-22027 | HIGH | 7.5 | 1.2% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauth... |
| CVE-2021-22026 | HIGH | 7.5 | 1.1% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauth... |
| CVE-2021-22025 | HIGH | 7.5 | 0.8% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthe... |
| CVE-2021-22024 | HIGH | 7.5 | 1.0% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthentic... |
| CVE-2021-22023 | HIGH | 7.2 | 1.0% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor wi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now