2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0229 | MEDIUM | 5.3 | 1.2% | Apr 22, 2021 | An uncontrolled resource consumption vulnerability in Message Queue Telemetry Transport (MQTT) server of Juniper Network... |
| CVE-2021-0228 | MEDIUM | 6.5 | 0.4% | Apr 22, 2021 | An improper check for unusual or exceptional conditions vulnerability in Juniper Networks MX Series platforms with Trio-... |
| CVE-2021-0227 | HIGH | 7.5 | 1.3% | Apr 22, 2021 | An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-... |
| CVE-2021-0226 | HIGH | 7.5 | 0.9% | Apr 22, 2021 | On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP sessio... |
| CVE-2021-0225 | MEDIUM | 5.8 | 0.7% | Apr 22, 2021 | An Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OS Evolved may cause the stateless fir... |
| CVE-2021-0224 | MEDIUM | 6.5 | 0.4% | Apr 22, 2021 | A vulnerability in the handling of internal resources necessary to bring up a large number of Layer 2 broadband remote a... |
| CVE-2021-0216 | MEDIUM | 6.5 | 0.4% | Apr 22, 2021 | A vulnerability in Juniper Networks Junos OS running on the ACX5448 and ACX710 platforms may cause BFD sessions to flap ... |
| CVE-2021-0214 | MEDIUM | 6.5 | 0.5% | Apr 22, 2021 | A vulnerability in the distributed or centralized periodic packet management daemon (PPMD) of Juniper Networks Junos OS ... |
| CVE-2021-3496 | HIGH | 7.8 | 1.1% | Apr 22, 2021 | A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file. |
| CVE-2021-20590 | HIGH | 7.5 | 1.3% | Apr 22, 2021 | Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 seri... |
| CVE-2021-31572 | CRITICAL | 9.8 | 1.4% | Apr 22, 2021 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer. |
| CVE-2021-31571 | CRITICAL | 9.8 | 1.4% | Apr 22, 2021 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation. |
| CVE-2021-30356 | HIGH | 8.1 | 1.0% | Apr 22, 2021 | A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low ... |
| CVE-2021-28168 | MEDIUM | 5.5 | 0.9% | Apr 22, 2021 | Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. Thi... |
| CVE-2021-27278 | HIGH | 8.2 | 0.5% | Apr 22, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-4... |
| CVE-2021-27277 | HIGH | 7.8 | 1.1% | Apr 22, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual I... |
| CVE-2021-23133 | HIGH | 7 | 0.5% | Apr 22, 2021 | A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalatio... |
| CVE-2021-30476 | CRITICAL | 9.8 | 1.6% | Apr 22, 2021 | HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Va... |
| CVE-2021-29653 | HIGH | 7.5 | 0.6% | Apr 22, 2021 | HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired cer... |
| CVE-2021-27400 | HIGH | 7.5 | 0.6% | Apr 22, 2021 | HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not... |
| CVE-2021-22540 | MEDIUM | 6.1 | 0.7% | Apr 22, 2021 | Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering.... |
| CVE-2021-27736 | MEDIUM | 6.5 | 1.3% | Apr 22, 2021 | FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFro... |
| CVE-2021-3287 | CRITICAL | 9.8 | 51.3% | Apr 22, 2021 | Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the ... |
| CVE-2021-31555 | HIGH | 7.5 | 0.8% | Apr 22, 2021 | An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka o... |
| CVE-2021-31554 | MEDIUM | 5.4 | 0.5% | Apr 22, 2021 | An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now