2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21546 | MEDIUM | 5.5 | 0.2% | Jul 29, 2021 | Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vuln... |
| CVE-2021-21538 | CRITICAL | 10 | 1.7% | Jul 29, 2021 | Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability... |
| CVE-2021-20505 | MEDIUM | 4.4 | 0.5% | Jul 29, 2021 | The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange ... |
| CVE-2021-37578 | CRITICAL | 9.8 | 4.1% | Jul 29, 2021 | Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provi... |
| CVE-2021-23417 | CRITICAL | 9.8 | 1.1% | Jul 28, 2021 | All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function. |
| CVE-2021-23416 | MEDIUM | 6.1 | 0.8% | Jul 28, 2021 | This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitiz... |
| CVE-2021-23415 | HIGH | 7.5 | 1.7% | Jul 28, 2021 | This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it... |
| CVE-2021-32001 | MEDIUM | 6.5 | 0.3% | Jul 28, 2021 | K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the... |
| CVE-2021-32000 | HIGH | 7.1 | 0.3% | Jul 28, 2021 | A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up i... |
| CVE-2021-23414 | MEDIUM | 6.1 | 2.6% | Jul 28, 2021 | This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execu... |
| CVE-2021-32796 | MEDIUM | 5.3 | 1.3% | Jul 27, 2021 | xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. x... |
| CVE-2021-32788 | MEDIUM | 4.3 | 0.9% | Jul 27, 2021 | Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post cre... |
| CVE-2021-32748 | MEDIUM | 4.3 | 1.0% | Jul 27, 2021 | Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Plat... |
| CVE-2021-34432 | HIGH | 7.5 | 1.2% | Jul 27, 2021 | In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with... |
| CVE-2021-20562 | MEDIUM | 5.4 | 0.9% | Jul 27, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-s... |
| CVE-2021-20399 | CRITICAL | 9.1 | 1.8% | Jul 27, 2021 | IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) att... |
| CVE-2021-37576 | HIGH | 7.8 | 0.6% | Jul 26, 2021 | arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to c... |
| CVE-2021-37555 | CRITICAL | 9.8 | 1.4% | Jul 26, 2021 | TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-1673... |
| CVE-2021-32795 | MEDIUM | 5.9 | 1.7% | Jul 26, 2021 | ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In ... |
| CVE-2021-32794 | HIGH | 7.5 | 1.0% | Jul 26, 2021 | ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due... |
| CVE-2021-37478 | CRITICAL | 9.8 | 2.2% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, whic... |
| CVE-2021-37477 | CRITICAL | 9.8 | 2.2% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `childre... |
| CVE-2021-37476 | CRITICAL | 9.8 | 2.2% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` throu... |
| CVE-2021-37475 | CRITICAL | 9.8 | 2.5% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `templat... |
| CVE-2021-37473 | CRITICAL | 9.8 | 2.2% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now