2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25655 | MEDIUM | 6.1 | 0.4% | Jun 24, 2021 | A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any un... |
| CVE-2021-25653 | HIGH | 7.8 | 0.6% | Jun 24, 2021 | A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) tha... |
| CVE-2021-25652 | MEDIUM | 5.5 | 0.7% | Jun 24, 2021 | An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virt... |
| CVE-2021-25651 | HIGH | 7.8 | 0.5% | Jun 24, 2021 | A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us... |
| CVE-2021-25650 | HIGH | 8.8 | 0.5% | Jun 24, 2021 | A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us... |
| CVE-2021-25649 | MEDIUM | 5.5 | 0.6% | Jun 24, 2021 | An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Servic... |
| CVE-2021-28800 | CRITICAL | 9.8 | 1.4% | Jun 24, 2021 | A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, thi... |
| CVE-2021-35041 | HIGH | 7.5 | 1.3% | Jun 24, 2021 | The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A mali... |
| CVE-2021-32823 | LOW | 3.7 | 1.9% | Jun 24, 2021 | In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions ... |
| CVE-2021-2322 | HIGH | 8.8 | 1.4% | Jun 23, 2021 | Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior. Easily exploitable vulne... |
| CVE-2021-34071 | MEDIUM | 5.5 | 0.7% | Jun 23, 2021 | Heap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the applicat... |
| CVE-2021-34070 | MEDIUM | 5.5 | 0.8% | Jun 23, 2021 | Out-of-bounds Read in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with... |
| CVE-2021-34069 | MEDIUM | 5.5 | 0.8% | Jun 23, 2021 | Divide-by-zero bug in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with... |
| CVE-2021-34068 | MEDIUM | 5.5 | 0.8% | Jun 23, 2021 | Heap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the applicat... |
| CVE-2021-34067 | MEDIUM | 5.5 | 0.8% | Jun 23, 2021 | Heap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the applicat... |
| CVE-2021-21809 | CRITICAL | 9.1 | 24.2% | Jun 23, 2021 | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted s... |
| CVE-2021-20019 | HIGH | 7.5 | 1.4% | Jun 23, 2021 | A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this c... |
| CVE-2021-29620 | HIGH | 7.5 | 2.2% | Jun 23, 2021 | Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML par... |
| CVE-2021-3526 | — | — | — | Jun 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2021-33624 | MEDIUM | 4.7 | 0.9% | Jun 23, 2021 | In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusi... |
| CVE-2021-35438 | MEDIUM | 6.1 | 1.0% | Jun 23, 2021 | phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of... |
| CVE-2021-25950 | — | — | — | Jun 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-28977 | MEDIUM | 4.8 | 0.5% | Jun 23, 2021 | Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file h... |
| CVE-2021-28976 | HIGH | 7.2 | 7.5% | Jun 23, 2021 | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess. |
| CVE-2021-31586 | HIGH | 8.8 | 44.1% | Jun 23, 2021 | Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now