2021 CVE Vulnerabilities
23,464 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26095 | HIGH | 8.8 | 0.7% | Jul 20, 2021 | The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 thr... |
| CVE-2021-24022 | MEDIUM | 4.4 | 0.2% | Jul 20, 2021 | A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 ... |
| CVE-2021-22125 | HIGH | 7.2 | 1.4% | Jul 20, 2021 | An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow ... |
| CVE-2021-36980 | MEDIUM | 5.5 | 1.2% | Jul 20, 2021 | Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_... |
| CVE-2021-36979 | MEDIUM | 5.5 | 0.9% | Jul 20, 2021 | Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb... |
| CVE-2021-36978 | MEDIUM | 5.5 | 1.3% | Jul 20, 2021 | QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from... |
| CVE-2021-36977 | MEDIUM | 6.5 | 1.5% | Jul 20, 2021 | matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based buffer overflow in H5MM_memcpy (called from H5MM_mal... |
| CVE-2021-36976 | MEDIUM | 6.5 | 2.8% | Jul 20, 2021 | libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). |
| CVE-2021-35054 | HIGH | 7.5 | 1.4% | Jul 20, 2021 | Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON file... |
| CVE-2021-26083 | MEDIUM | 5.4 | 0.6% | Jul 20, 2021 | Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6... |
| CVE-2021-26082 | MEDIUM | 5.4 | 0.7% | Jul 20, 2021 | The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, an... |
| CVE-2021-26081 | MEDIUM | 5.3 | 1.2% | Jul 20, 2021 | REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from... |
| CVE-2021-32774 | MEDIUM | 5.4 | 0.5% | Jul 20, 2021 | DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b... |
| CVE-2021-32773 | HIGH | 7.5 | 0.9% | Jul 20, 2021 | Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior t... |
| CVE-2021-3135 | MEDIUM | 6.1 | 0.8% | Jul 19, 2021 | An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.... |
| CVE-2021-32760 | MEDIUM | 6.3 | 1.6% | Jul 19, 2021 | containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and ext... |
| CVE-2021-34618 | MEDIUM | 6.5 | 0.5% | Jul 19, 2021 | A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in versi... |
| CVE-2021-34617 | MEDIUM | 6.1 | 0.6% | Jul 19, 2021 | A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve... |
| CVE-2021-31590 | HIGH | 8.8 | 2.7% | Jul 19, 2021 | PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. ... |
| CVE-2021-34821 | MEDIUM | 6.1 | 0.8% | Jul 19, 2021 | Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2. The WebUI has wrong HTTP ... |
| CVE-2021-34820 | HIGH | 7.5 | 4.0% | Jul 19, 2021 | Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for ... |
| CVE-2021-36799 | HIGH | 8.8 | 0.4% | Jul 19, 2021 | KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local use... |
| CVE-2021-36797 | MEDIUM | 6.8 | 0.3% | Jul 19, 2021 | In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device.... |
| CVE-2021-34676 | HIGH | 7.5 | 1.8% | Jul 19, 2021 | Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation. |
| CVE-2021-34675 | HIGH | 7.5 | 1.8% | Jul 19, 2021 | Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now