2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21005 | HIGH | 7.5 | 0.7% | Jun 25, 2021 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet wi... |
| CVE-2021-21004 | MEDIUM | 6.1 | 0.6% | Jun 25, 2021 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP fr... |
| CVE-2021-21003 | MEDIUM | 5.3 | 0.9% | Jun 25, 2021 | In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Serv... |
| CVE-2021-21002 | HIGH | 7.5 | 1.0% | Jun 25, 2021 | In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denia... |
| CVE-2021-29677 | MEDIUM | 5.4 | 0.5% | Jun 25, 2021 | IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerabil... |
| CVE-2021-29676 | MEDIUM | 5.4 | 0.8% | Jun 25, 2021 | IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victi... |
| CVE-2021-20583 | MEDIUM | 4.9 | 0.9% | Jun 25, 2021 | IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP G... |
| CVE-2021-32702 | MEDIUM | 6.1 | 1.4% | Jun 25, 2021 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and inc... |
| CVE-2021-3314 | MEDIUM | 6.1 | 0.9% | Jun 25, 2021 | Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an adm... |
| CVE-2021-35501 | MEDIUM | 5.4 | 1.0% | Jun 25, 2021 | PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an admini... |
| CVE-2021-34074 | CRITICAL | 9.8 | 7.5% | Jun 25, 2021 | PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass t... |
| CVE-2021-34185 | HIGH | 7.8 | 0.7% | Jun 25, 2021 | Miniaudio 0.10.35 has an integer-based buffer overflow caused by an out-of-bounds left shift in drwav_bytes_to_u32 in mi... |
| CVE-2021-34184 | CRITICAL | 9.8 | 1.1% | Jun 25, 2021 | Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in m... |
| CVE-2021-34183 | — | — | — | Jun 25, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-33895 | HIGH | 8.1 | 0.9% | Jun 25, 2021 | ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running B... |
| CVE-2021-27043 | HIGH | 7.8 | 0.9% | Jun 25, 2021 | An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application ... |
| CVE-2021-27042 | HIGH | 7.8 | 1.8% | Jun 25, 2021 | A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerabili... |
| CVE-2021-27041 | HIGH | 7.8 | 1.7% | Jun 25, 2021 | A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerabil... |
| CVE-2021-27040 | LOW | 3.3 | 2.7% | Jun 25, 2021 | A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnera... |
| CVE-2021-35050 | HIGH | 7.5 | 1.0% | Jun 25, 2021 | User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an a... |
| CVE-2021-35049 | HIGH | 8.8 | 4.6% | Jun 25, 2021 | Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web inter... |
| CVE-2021-35048 | CRITICAL | 9.8 | 1.3% | Jun 25, 2021 | Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interfa... |
| CVE-2021-35047 | HIGH | 8.8 | 1.6% | Jun 25, 2021 | Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker ... |
| CVE-2021-31615 | MEDIUM | 5.3 | 0.4% | Jun 25, 2021 | Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent ... |
| CVE-2021-28958 | CRITICAL | 9.8 | 73.1% | Jun 25, 2021 | Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now