2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20414 | MEDIUM | 4.9 | 0.5% | Jul 12, 2021 | IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly l... |
| CVE-2021-33807 | HIGH | 7.5 | 14.1% | Jul 12, 2021 | Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData. |
| CVE-2021-33037 | MEDIUM | 5.3 | 75.4% | Jul 12, 2021 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-enco... |
| CVE-2021-30640 | MEDIUM | 6.5 | 9.9% | Jul 12, 2021 | A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user n... |
| CVE-2021-30639 | HIGH | 7.5 | 6.9% | Jul 12, 2021 | A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part... |
| CVE-2021-36383 | MEDIUM | 4.3 | 0.7% | Jul 12, 2021 | Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by mod... |
| CVE-2021-36382 | LOW | 3.7 | 0.5% | Jul 12, 2021 | Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-t... |
| CVE-2021-32688 | HIGH | 8.8 | 2.3% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens... |
| CVE-2021-32680 | LOW | 3.3 | 0.4% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Ne... |
| CVE-2021-26088 | CRITICAL | 9.6 | 1.0% | Jul 12, 2021 | An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user t... |
| CVE-2021-24015 | HIGH | 8.8 | 1.2% | Jul 12, 2021 | An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of Fo... |
| CVE-2021-24013 | MEDIUM | 6.5 | 1.1% | Jul 12, 2021 | Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unau... |
| CVE-2021-36377 | HIGH | 7.5 | 0.6% | Jul 12, 2021 | Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation. |
| CVE-2021-32679 | HIGH | 8.8 | 1.4% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, fi... |
| CVE-2021-32678 | MEDIUM | 5.3 | 1.4% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ra... |
| CVE-2021-26090 | HIGH | 7.5 | 1.3% | Jul 12, 2021 | A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 a... |
| CVE-2021-26089 | HIGH | 7.8 | 0.4% | Jul 12, 2021 | An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitra... |
| CVE-2021-35064 | CRITICAL | 9.8 | 70.8% | Jul 12, 2021 | KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn... |
| CVE-2021-30129 | MEDIUM | 6.5 | 3.4% | Jul 12, 2021 | A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error.... |
| CVE-2021-3547 | HIGH | 7.4 | 1.0% | Jul 12, 2021 | OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authenticatio... |
| CVE-2021-35037 | MEDIUM | 6.1 | 0.6% | Jul 12, 2021 | Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their... |
| CVE-2021-27293 | HIGH | 7.5 | 1.5% | Jul 12, 2021 | RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (R... |
| CVE-2021-22921 | HIGH | 7.8 | 7.4% | Jul 12, 2021 | Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions... |
| CVE-2021-22918 | MEDIUM | 5.3 | 23.1% | Jul 12, 2021 | Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to conver... |
| CVE-2021-22917 | MEDIUM | 6.5 | 1.2% | Jul 12, 2021 | Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in T... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now