2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31799 | HIGH | 7 | 1.5% | Jul 30, 2021 | In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code ... |
| CVE-2021-30483 | MEDIUM | 5.3 | 2.2% | Jul 30, 2021 | isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository. |
| CVE-2021-30124 | CRITICAL | 9.8 | 3.0% | Jul 30, 2021 | The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attacker... |
| CVE-2021-28966 | HIGH | 7.5 | 58.0% | Jul 30, 2021 | In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter w... |
| CVE-2021-28674 | MEDIUM | 5.4 | 0.9% | Jul 30, 2021 | The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node ... |
| CVE-2021-28095 | MEDIUM | 4.8 | 0.9% | Jul 30, 2021 | OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash coll... |
| CVE-2021-28094 | MEDIUM | 6.5 | 1.1% | Jul 30, 2021 | OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, ... |
| CVE-2021-28093 | MEDIUM | 6.5 | 1.1% | Jul 30, 2021 | OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due ... |
| CVE-2021-25200 | CRITICAL | 9.8 | 1.9% | Jul 30, 2021 | Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbit... |
| CVE-2021-20789 | MEDIUM | 6.1 | 0.9% | Jul 30, 2021 | Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, G... |
| CVE-2021-20788 | MEDIUM | 4.3 | 0.9% | Jul 30, 2021 | Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version... |
| CVE-2021-20787 | MEDIUM | 4.8 | 0.6% | Jul 30, 2021 | Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5... |
| CVE-2021-20786 | MEDIUM | 4.3 | 0.4% | Jul 30, 2021 | Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version ... |
| CVE-2021-20785 | MEDIUM | 4.8 | 0.6% | Jul 30, 2021 | Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5... |
| CVE-2021-20783 | HIGH | 8.8 | 0.6% | Jul 30, 2021 | Cross-site request forgery (CSRF) vulnerability in Optical BB unit E-WMTA2.3 allows a remote attacker to hijack the auth... |
| CVE-2021-20114 | HIGH | 7.5 | 6.0% | Jul 30, 2021 | When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the ... |
| CVE-2021-20113 | MEDIUM | 5.3 | 1.3% | Jul 30, 2021 | An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for ... |
| CVE-2021-20112 | MEDIUM | 5.4 | 0.6% | Jul 30, 2021 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.ph... |
| CVE-2021-20111 | MEDIUM | 5.4 | 0.6% | Jul 30, 2021 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php wit... |
| CVE-2021-29781 | CRITICAL | 9.8 | 2.9% | Jul 30, 2021 | IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an u... |
| CVE-2021-29736 | HIGH | 8.8 | 1.1% | Jul 30, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the sys... |
| CVE-2021-36742 | HIGH | 7.8 | 1.5% | Jul 29, 2021 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free B... |
| CVE-2021-36741 | HIGH | 8.8 | 5.0% | Jul 29, 2021 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free... |
| CVE-2021-25273 | MEDIUM | 4.8 | 0.8% | Jul 29, 2021 | Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706. |
| CVE-2021-23418 | CRITICAL | 9.8 | 1.6% | Jul 29, 2021 | The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse unt... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now