2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22144 | MEDIUM | 6.5 | 1.7% | Jul 26, 2021 | In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial o... |
| CVE-2021-20560 | MEDIUM | 5.4 | 0.6% | Jul 26, 2021 | IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the click... |
| CVE-2021-20431 | MEDIUM | 6.5 | 0.9% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an ... |
| CVE-2021-20430 | MEDIUM | 5.3 | 1.3% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi... |
| CVE-2021-20337 | HIGH | 7.5 | 0.7% | Jul 26, 2021 | IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that cou... |
| CVE-2021-33900 | HIGH | 7.5 | 0.8% | Jul 26, 2021 | While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL auth... |
| CVE-2021-36092 | MEDIUM | 6.1 | 0.7% | Jul 26, 2021 | It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This is... |
| CVE-2021-36091 | MEDIUM | 4.3 | 0.7% | Jul 26, 2021 | Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS))... |
| CVE-2021-21443 | MEDIUM | 4.3 | 0.9% | Jul 26, 2021 | Agents are able to list customer user emails without required permissions in the bulk action screen. This issue affects:... |
| CVE-2021-21442 | MEDIUM | 5.4 | 0.6% | Jul 26, 2021 | In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed... |
| CVE-2021-21440 | MEDIUM | 6.5 | 0.8% | Jul 26, 2021 | Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: O... |
| CVE-2021-37449 | MEDIUM | 5.4 | 0.5% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected). |
| CVE-2021-37448 | MEDIUM | 5.4 | 0.5% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored). |
| CVE-2021-37447 | HIGH | 8.1 | 1.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file ... |
| CVE-2021-37446 | MEDIUM | 4.3 | 1.2% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file re... |
| CVE-2021-37445 | MEDIUM | 6.5 | 1.4% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading... |
| CVE-2021-37444 | HIGH | 8.8 | 1.9% | Jul 25, 2021 | NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.... |
| CVE-2021-37443 | HIGH | 8.1 | 1.2% | Jul 25, 2021 | NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion. |
| CVE-2021-37442 | MEDIUM | 6.5 | 1.2% | Jul 25, 2021 | NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files. |
| CVE-2021-37441 | HIGH | 8.8 | 1.5% | Jul 25, 2021 | NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring. |
| CVE-2021-37440 | MEDIUM | 6.5 | 1.2% | Jul 25, 2021 | NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring. |
| CVE-2021-37439 | MEDIUM | 6.5 | 1.2% | Jul 25, 2021 | NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability. |
| CVE-2021-37470 | MEDIUM | 5.4 | 0.6% | Jul 25, 2021 | In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user... |
| CVE-2021-37469 | MEDIUM | 6.5 | 1.2% | Jul 25, 2021 | In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the ... |
| CVE-2021-37468 | LOW | 3.3 | 0.2% | Jul 25, 2021 | NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration file... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now