2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38927 | MEDIUM | 6.1 | 0.3% | Dec 25, 2023 | IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS... |
| CVE-2021-22962 | CRITICAL | 9.1 | 91.0% | Dec 19, 2023 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource... |
| CVE-2021-42797 | HIGH | 7.5 | 1.0% | Dec 16, 2023 | Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthentic... |
| CVE-2021-42796 | CRITICAL | 9.8 | 1.1% | Dec 16, 2023 | An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that a... |
| CVE-2021-42794 | MEDIUM | 5.3 | 1.2% | Dec 16, 2023 | An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a ... |
| CVE-2021-3187 | HIGH | 8.8 | 0.6% | Dec 11, 2023 | An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can ... |
| CVE-2021-46899 | HIGH | 7.8 | 0.2% | Dec 9, 2023 | SyncTrayzor 1.1.29 enables CEF (Chromium Embedded Framework) remote debugging, allowing a local attacker to control the ... |
| CVE-2021-27795 | HIGH | 8.1 | 0.2% | Dec 6, 2023 | Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the licen... |
| CVE-2021-35975 | MEDIUM | 5.3 | 1.1% | Nov 30, 2023 | Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius... |
| CVE-2021-36806 | MEDIUM | 6.1 | 0.4% | Nov 30, 2023 | A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sop... |
| CVE-2021-39008 | MEDIUM | 4.9 | 0.6% | Nov 23, 2023 | IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a privileged user to obtain sensitive information due to mi... |
| CVE-2021-37942 | HIGH | 7.8 | 0.2% | Nov 22, 2023 | A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a maliciou... |
| CVE-2021-37937 | HIGH | 8.8 | 0.7% | Nov 22, 2023 | An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with ... |
| CVE-2021-22143 | MEDIUM | 4.3 | 0.6% | Nov 22, 2023 | The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application err... |
| CVE-2021-22151 | MEDIUM | 4.3 | 0.7% | Nov 22, 2023 | It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a m... |
| CVE-2021-22150 | HIGH | 7.2 | 1.2% | Nov 22, 2023 | It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older versi... |
| CVE-2021-22142 | HIGH | 8.8 | 1.0% | Nov 22, 2023 | Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable... |
| CVE-2021-38405 | HIGH | 7.8 | 1.3% | Nov 21, 2023 | The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specia... |
| CVE-2021-27504 | HIGH | 7.8 | 0.3% | Nov 21, 2023 | Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values,... |
| CVE-2021-27502 | HIGH | 7.8 | 0.3% | Nov 21, 2023 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buff... |
| CVE-2021-27429 | HIGH | 7.8 | 0.3% | Nov 20, 2023 | Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an inte... |
| CVE-2021-22636 | HIGH | 7.8 | 0.3% | Nov 20, 2023 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a smal... |
| CVE-2021-35437 | CRITICAL | 9.8 | 1.0% | Nov 16, 2023 | SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class. |
| CVE-2021-46774 | HIGH | 7.5 | 0.5% | Nov 14, 2023 | Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an inva... |
| CVE-2021-46766 | MEDIUM | 5.5 | 0.2% | Nov 14, 2023 | Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now