2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29479MEDIUM6.1Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied `X-Forwarded-Host` heade...
CVE-2021-34824HIGH8.8Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified i...
CVE-2021-31531CRITICAL9.8Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
CVE-2021-31530HIGH7.5Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.
CVE-2021-31160HIGH7.5Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.
CVE-2021-34550HIGH7.5An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of...
CVE-2021-34549HIGH7.5An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circui...
CVE-2021-32565HIGH7.5Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This i...
CVE-2021-28691HIGH7.8Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to ...
CVE-2021-28690MEDIUM6.5x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vu...
CVE-2021-27577HIGH7.5Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This i...
CVE-2021-23400HIGH8.8The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain n...
CVE-2021-22545HIGH7.8An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. ...
CVE-2021-34548HIGH7.5An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to ...
CVE-2021-33503HIGH7.5An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority...
CVE-2021-31838CRITICAL9.1A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to t...
CVE-2021-1134HIGH7.4A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could a...
CVE-2021-35303MEDIUM6.1Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML v...
CVE-2021-35302MEDIUM5.3Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive info...
CVE-2021-35301MEDIUM5.3Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Tic...
CVE-2021-35300MEDIUM4.3Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users...
CVE-2021-35299HIGH7.5Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connecti...
CVE-2021-35298MEDIUM6.1Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML v...
CVE-2021-32723MEDIUM6.5Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Serv...
CVE-2021-32722MEDIUM6.5GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an u...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now