2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21664MEDIUM6.5An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Cre...
CVE-2021-21663MEDIUM4.3A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read pe...
CVE-2021-21662MEDIUM4.3A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read p...
CVE-2021-21661MEDIUM4.3Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing ...
CVE-2021-31929MEDIUM4.3Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and se...
CVE-2021-3041HIGH7.8A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that e...
CVE-2021-3040HIGH7.2An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when proce...
CVE-2021-3039LOW3.8An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console whe...
CVE-2021-31998HIGH7.8A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE B...
CVE-2021-31997HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local a...
CVE-2021-25949CRITICAL9.8Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may ...
CVE-2021-25948CRITICAL9.8Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of ...
CVE-2021-25322HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local ...
CVE-2021-21736HIGH7.2A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user pe...
CVE-2021-21735MEDIUM6.5A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user...
CVE-2021-20293MEDIUM6.1A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where i...
CVE-2021-20081HIGH7.2Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticate...
CVE-2021-34539HIGH7.2An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an...
CVE-2021-34363CRITICAL9.1The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion vi...
CVE-2021-30641MEDIUM5.3Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
CVE-2021-26691CRITICAL9.8In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a ...
CVE-2021-26690HIGH7.5Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL po...
CVE-2021-3588LOW3.3The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before us...
CVE-2021-33393HIGH8.8lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It...
CVE-2021-0134MEDIUM4.9Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now