2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29479 | MEDIUM | 6.1 | 0.9% | Jun 29, 2021 | Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied `X-Forwarded-Host` heade... |
| CVE-2021-34824 | HIGH | 8.8 | 2.0% | Jun 29, 2021 | Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified i... |
| CVE-2021-31531 | CRITICAL | 9.8 | 2.4% | Jun 29, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). |
| CVE-2021-31530 | HIGH | 7.5 | 2.9% | Jun 29, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure. |
| CVE-2021-31160 | HIGH | 7.5 | 3.5% | Jun 29, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data. |
| CVE-2021-34550 | HIGH | 7.5 | 1.6% | Jun 29, 2021 | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of... |
| CVE-2021-34549 | HIGH | 7.5 | 1.6% | Jun 29, 2021 | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circui... |
| CVE-2021-32565 | HIGH | 7.5 | 2.1% | Jun 29, 2021 | Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This i... |
| CVE-2021-28691 | HIGH | 7.8 | 0.4% | Jun 29, 2021 | Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to ... |
| CVE-2021-28690 | MEDIUM | 6.5 | 1.0% | Jun 29, 2021 | x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vu... |
| CVE-2021-27577 | HIGH | 7.5 | 3.5% | Jun 29, 2021 | Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This i... |
| CVE-2021-23400 | HIGH | 8.8 | 1.4% | Jun 29, 2021 | The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain n... |
| CVE-2021-22545 | HIGH | 7.8 | 0.2% | Jun 29, 2021 | An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. ... |
| CVE-2021-34548 | HIGH | 7.5 | 2.7% | Jun 29, 2021 | An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to ... |
| CVE-2021-33503 | HIGH | 7.5 | 3.3% | Jun 29, 2021 | An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority... |
| CVE-2021-31838 | CRITICAL | 9.1 | 2.0% | Jun 29, 2021 | A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to t... |
| CVE-2021-1134 | HIGH | 7.4 | 0.8% | Jun 29, 2021 | A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could a... |
| CVE-2021-35303 | MEDIUM | 6.1 | 0.8% | Jun 28, 2021 | Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML v... |
| CVE-2021-35302 | MEDIUM | 5.3 | 1.2% | Jun 28, 2021 | Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive info... |
| CVE-2021-35301 | MEDIUM | 5.3 | 1.2% | Jun 28, 2021 | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Tic... |
| CVE-2021-35300 | MEDIUM | 4.3 | 0.9% | Jun 28, 2021 | Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users... |
| CVE-2021-35299 | HIGH | 7.5 | 1.1% | Jun 28, 2021 | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connecti... |
| CVE-2021-35298 | MEDIUM | 6.1 | 1.1% | Jun 28, 2021 | Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML v... |
| CVE-2021-32723 | MEDIUM | 6.5 | 1.4% | Jun 28, 2021 | Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Serv... |
| CVE-2021-32722 | MEDIUM | 6.5 | 1.3% | Jun 28, 2021 | GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an u... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now