2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23017 | HIGH | 7.7 | 52.8% | Jun 1, 2021 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t... |
| CVE-2021-27828 | CRITICAL | 9.1 | 20.3% | Jun 1, 2021 | SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the a... |
| CVE-2021-25932 | MEDIUM | 5.4 | 0.9% | Jun 1, 2021 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation... |
| CVE-2021-23018 | HIGH | 7.4 | 0.5% | Jun 1, 2021 | Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are us... |
| CVE-2021-33790 | CRITICAL | 9.8 | 2.8% | May 31, 2021 | The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputSt... |
| CVE-2021-33564 | CRITICAL | 9.8 | 72.2% | May 29, 2021 | An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write... |
| CVE-2021-31703 | CRITICAL | 9.8 | 1.2% | May 29, 2021 | Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by... |
| CVE-2021-31702 | HIGH | 7.5 | 1.2% | May 29, 2021 | Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated b... |
| CVE-2021-30461 | CRITICAL | 9.8 | 36.6% | May 29, 2021 | A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,... |
| CVE-2021-32635 | MEDIUM | 6.3 | 1.4% | May 28, 2021 | Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `si... |
| CVE-2021-32621 | HIGH | 8.8 | 2.1% | May 28, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri... |
| CVE-2021-32620 | HIGH | 8.8 | 1.1% | May 28, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri... |
| CVE-2021-32619 | CRITICAL | 9.8 | 1.1% | May 28, 2021 | Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, mod... |
| CVE-2021-32616 | MEDIUM | 6.1 | 0.7% | May 28, 2021 | 1CDN is open-source file sharing software. In 1CDN before commit f88a2730fa50fc2c2aeab09011f6f142fd90ec25, there is a ba... |
| CVE-2021-29507 | MEDIUM | 6.5 | 0.7% | May 28, 2021 | GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2... |
| CVE-2021-29505 | HIGH | 8.8 | 77.7% | May 28, 2021 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4... |
| CVE-2021-29492 | HIGH | 8.3 | 68.4% | May 28, 2021 | Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP... |
| CVE-2021-33587 | HIGH | 7.5 | 2.3% | May 28, 2021 | The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity r... |
| CVE-2021-22519 | CRITICAL | 9.8 | 2.0% | May 28, 2021 | Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), ... |
| CVE-2021-20267 | HIGH | 7.1 | 1.0% | May 28, 2021 | A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyon... |
| CVE-2021-33623 | HIGH | 7.5 | 2.8% | May 28, 2021 | The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denia... |
| CVE-2021-32646 | HIGH | 7.3 | 0.7% | May 28, 2021 | Roomer is a discord bot cog (extension) which provides automatic voice channel generation as well as private voice and t... |
| CVE-2021-32642 | CRITICAL | 9.4 | 1.3% | May 28, 2021 | radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validatio... |
| CVE-2021-32637 | CRITICAL | 10 | 1.9% | May 28, 2021 | Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_req... |
| CVE-2021-3514 | MEDIUM | 6.5 | 1.2% | May 28, 2021 | When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a spe... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now