2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30031 | — | — | — | Apr 21, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-21647 | MEDIUM | 4.3 | 1.5% | Apr 21, 2021 | Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attacke... |
| CVE-2021-21646 | HIGH | 8.8 | 1.7% | Apr 21, 2021 | Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plug... |
| CVE-2021-21645 | MEDIUM | 4.3 | 0.9% | Apr 21, 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, atta... |
| CVE-2021-21644 | MEDIUM | 5.4 | 1.1% | Apr 21, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attack... |
| CVE-2021-21643 | MEDIUM | 6.5 | 1.1% | Apr 21, 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpo... |
| CVE-2021-21642 | HIGH | 8.1 | 37.8% | Apr 21, 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (... |
| CVE-2021-20501 | HIGH | 8.2 | 1.3% | Apr 21, 2021 | IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to th... |
| CVE-2021-20454 | HIGH | 8.2 | 2.9% | Apr 21, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack wh... |
| CVE-2021-28965 | HIGH | 7.5 | 5.1% | Apr 21, 2021 | The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML ... |
| CVE-2021-29462 | CRITICAL | 9.8 | 0.6% | Apr 20, 2021 | The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server pa... |
| CVE-2021-29461 | HIGH | 8.8 | 2.5% | Apr 20, 2021 | Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in ... |
| CVE-2021-30464 | HIGH | 7.5 | 1.2% | Apr 20, 2021 | OMICRON StationGuard before 1.10 allows remote attackers to cause a denial of service (connectivity outage) via crafted ... |
| CVE-2021-29459 | MEDIUM | 6.1 | 1.1% | Apr 20, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible ... |
| CVE-2021-28829 | HIGH | 8 | 0.7% | Apr 20, 2021 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ... |
| CVE-2021-28828 | HIGH | 8.8 | 0.8% | Apr 20, 2021 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ... |
| CVE-2021-28827 | CRITICAL | 9.6 | 1.1% | Apr 20, 2021 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ... |
| CVE-2021-21526 | MEDIUM | 6.7 | 0.3% | Apr 20, 2021 | Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmi... |
| CVE-2021-30496 | MEDIUM | 5.7 | 1.2% | Apr 20, 2021 | The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the... |
| CVE-2021-29155 | MEDIUM | 5.5 | 1.1% | Apr 20, 2021 | An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds spe... |
| CVE-2021-28492 | MEDIUM | 4.9 | 0.8% | Apr 20, 2021 | Unisys Stealth (core) 5.x before 5.0.048.0, 5.1.x before 5.1.017.0, and 6.x before 6.0.037.0 stores passwords in a recov... |
| CVE-2021-28156 | HIGH | 7.5 | 2.3% | Apr 20, 2021 | HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fix... |
| CVE-2021-1079 | MEDIUM | 6.1 | 0.3% | Apr 20, 2021 | NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugins where log files ar... |
| CVE-2021-28793 | CRITICAL | 9.8 | 1.6% | Apr 20, 2021 | vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folde... |
| CVE-2021-25681 | HIGH | 7.5 | 13.4% | Apr 20, 2021 | AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. T... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now