2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39113 | HIGH | 7.5 | 1.8% | Aug 30, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached c... |
| CVE-2021-39111 | MEDIUM | 6.1 | 1.0% | Aug 30, 2021 | The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from ve... |
| CVE-2021-26084 | CRITICAL | 9.8 | 100.0% | Aug 30, 2021 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un... |
| CVE-2021-39272 | MEDIUM | 5.9 | 0.9% | Aug 30, 2021 | Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation ... |
| CVE-2021-39271 | HIGH | 8.8 | 3.7% | Aug 30, 2021 | OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attack... |
| CVE-2021-38385 | HIGH | 7.5 | 1.7% | Aug 30, 2021 | Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-s... |
| CVE-2021-36359 | HIGH | 8.8 | 4.0% | Aug 30, 2021 | OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via XML tag injection beca... |
| CVE-2021-37749 | CRITICAL | 9.8 | 1.8% | Aug 30, 2021 | MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (wi... |
| CVE-2021-40178 | MEDIUM | 6.1 | 0.8% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings. |
| CVE-2021-40177 | CRITICAL | 9.8 | 4.6% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite. |
| CVE-2021-40176 | MEDIUM | 6.1 | 0.8% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5225 allows stored XSS. |
| CVE-2021-40175 | CRITICAL | 9.8 | 7.0% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. |
| CVE-2021-40174 | HIGH | 8.8 | 1.0% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings. |
| CVE-2021-40173 | HIGH | 8.8 | 1.0% | Aug 29, 2021 | Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings. |
| CVE-2021-40172 | HIGH | 8.8 | 1.0% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings. |
| CVE-2021-38154 | HIGH | 7.5 | 4.0% | Aug 29, 2021 | Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server ... |
| CVE-2021-39174 | HIGH | 8.8 | 3.9% | Aug 28, 2021 | Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges... |
| CVE-2021-39173 | HIGH | 8.8 | 2.4% | Aug 27, 2021 | Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges ... |
| CVE-2021-39172 | HIGH | 8.8 | 29.2% | Aug 27, 2021 | Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges... |
| CVE-2021-39171 | HIGH | 7.5 | 1.3% | Aug 27, 2021 | Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3... |
| CVE-2021-32759 | HIGH | 7.2 | 1.3% | Aug 27, 2021 | OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in ve... |
| CVE-2021-3264 | HIGH | 7.2 | 0.9% | Aug 27, 2021 | SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php. |
| CVE-2021-28700 | MEDIUM | 4.9 | 1.9% | Aug 27, 2021 | xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged... |
| CVE-2021-28699 | MEDIUM | 5.5 | 0.4% | Aug 27, 2021 | inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant ... |
| CVE-2021-28698 | MEDIUM | 5.5 | 0.3% | Aug 27, 2021 | long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the g... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now