2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21664 | MEDIUM | 6.5 | 1.0% | Jun 10, 2021 | An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Cre... |
| CVE-2021-21663 | MEDIUM | 4.3 | 1.0% | Jun 10, 2021 | A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read pe... |
| CVE-2021-21662 | MEDIUM | 4.3 | 0.9% | Jun 10, 2021 | A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read p... |
| CVE-2021-21661 | MEDIUM | 4.3 | 1.6% | Jun 10, 2021 | Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing ... |
| CVE-2021-31929 | MEDIUM | 4.3 | 0.5% | Jun 10, 2021 | Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and se... |
| CVE-2021-3041 | HIGH | 7.8 | 0.2% | Jun 10, 2021 | A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that e... |
| CVE-2021-3040 | HIGH | 7.2 | 1.3% | Jun 10, 2021 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when proce... |
| CVE-2021-3039 | LOW | 3.8 | 0.5% | Jun 10, 2021 | An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console whe... |
| CVE-2021-31998 | HIGH | 7.8 | 0.3% | Jun 10, 2021 | A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE B... |
| CVE-2021-31997 | HIGH | 7.8 | 0.3% | Jun 10, 2021 | A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local a... |
| CVE-2021-25949 | CRITICAL | 9.8 | 3.3% | Jun 10, 2021 | Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may ... |
| CVE-2021-25948 | CRITICAL | 9.8 | 3.3% | Jun 10, 2021 | Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of ... |
| CVE-2021-25322 | HIGH | 7.8 | 0.4% | Jun 10, 2021 | A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local ... |
| CVE-2021-21736 | HIGH | 7.2 | 0.9% | Jun 10, 2021 | A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user pe... |
| CVE-2021-21735 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user... |
| CVE-2021-20293 | MEDIUM | 6.1 | 0.9% | Jun 10, 2021 | A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where i... |
| CVE-2021-20081 | HIGH | 7.2 | 52.4% | Jun 10, 2021 | Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticate... |
| CVE-2021-34539 | HIGH | 7.2 | 1.2% | Jun 10, 2021 | An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an... |
| CVE-2021-34363 | CRITICAL | 9.1 | 1.8% | Jun 10, 2021 | The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion vi... |
| CVE-2021-30641 | MEDIUM | 5.3 | 52.3% | Jun 10, 2021 | Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' |
| CVE-2021-26691 | CRITICAL | 9.8 | 68.1% | Jun 10, 2021 | In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a ... |
| CVE-2021-26690 | HIGH | 7.5 | 65.1% | Jun 10, 2021 | Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL po... |
| CVE-2021-3588 | LOW | 3.3 | 0.4% | Jun 10, 2021 | The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before us... |
| CVE-2021-33393 | HIGH | 8.8 | 58.7% | Jun 9, 2021 | lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It... |
| CVE-2021-0134 | MEDIUM | 4.9 | 0.8% | Jun 9, 2021 | Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now