2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29659 | MEDIUM | 6.5 | 1.3% | May 20, 2021 | ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in t... |
| CVE-2021-27467 | MEDIUM | 6.1 | 0.7% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s ... |
| CVE-2021-27465 | MEDIUM | 6.1 | 0.6% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applicatio... |
| CVE-2021-27463 | MEDIUM | 5.3 | 0.9% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applicatio... |
| CVE-2021-27461 | HIGH | 7.5 | 1.4% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver ... |
| CVE-2021-27459 | CRITICAL | 9.8 | 1.8% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the af... |
| CVE-2021-27457 | HIGH | 7.5 | 0.5% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products u... |
| CVE-2021-20721 | CRITICAL | 9.8 | 1.5% | May 20, 2021 | KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the fil... |
| CVE-2021-20720 | CRITICAL | 9.8 | 1.3% | May 20, 2021 | SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL co... |
| CVE-2021-20719 | MEDIUM | 6.8 | 0.4% | May 20, 2021 | RFNTPS firmware versions System_01000004 and earlier, and Web_01000004 and earlier allow an attacker on the same network... |
| CVE-2021-20718 | HIGH | 7.5 | 3.4% | May 20, 2021 | mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified ve... |
| CVE-2021-29625 | MEDIUM | 6.1 | 9.6% | May 19, 2021 | Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4... |
| CVE-2021-29624 | MEDIUM | 6.5 | 0.8% | May 19, 2021 | fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fa... |
| CVE-2021-29622 | MEDIUM | 6.1 | 19.6% | May 19, 2021 | Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to... |
| CVE-2021-29503 | MEDIUM | 6.1 | 1.0% | May 19, 2021 | HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scriptin... |
| CVE-2021-27924 | MEDIUM | 5.9 | 0.5% | May 19, 2021 | An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session coo... |
| CVE-2021-20529 | MEDIUM | 5.3 | 0.9% | May 19, 2021 | IBM Control Center 6.2.0.0 could allow a user to obtain sensitive version information that could be used in further atta... |
| CVE-2021-20528 | MEDIUM | 5.4 | 0.5% | May 19, 2021 | IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2021-20374 | MEDIUM | 5.4 | 0.5% | May 19, 2021 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows user... |
| CVE-2021-31158 | MEDIUM | 6.5 | 0.7% | May 19, 2021 | In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctl... |
| CVE-2021-27925 | MEDIUM | 4.4 | 0.5% | May 19, 2021 | An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is en... |
| CVE-2021-25644 | HIGH | 7.5 | 0.6% | May 19, 2021 | An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API... |
| CVE-2021-33204 | CRITICAL | 9.8 | 2.2% | May 19, 2021 | In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achi... |
| CVE-2021-31930 | MEDIUM | 6.1 | 0.9% | May 19, 2021 | Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote at... |
| CVE-2021-3517 | HIGH | 8.6 | 8.3% | May 19, 2021 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now