2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-30031Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-21647MEDIUM4.3Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attacke...
CVE-2021-21646HIGH8.8Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plug...
CVE-2021-21645MEDIUM4.3Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, atta...
CVE-2021-21644MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attack...
CVE-2021-21643MEDIUM6.5Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpo...
CVE-2021-21642HIGH8.1Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (...
CVE-2021-20501HIGH8.2IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to th...
CVE-2021-20454HIGH8.2IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack wh...
CVE-2021-28965HIGH7.5The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML ...
CVE-2021-29462CRITICAL9.8The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server pa...
CVE-2021-29461HIGH8.8Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in ...
CVE-2021-30464HIGH7.5OMICRON StationGuard before 1.10 allows remote attackers to cause a denial of service (connectivity outage) via crafted ...
CVE-2021-29459MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible ...
CVE-2021-28829HIGH8The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ...
CVE-2021-28828HIGH8.8The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ...
CVE-2021-28827CRITICAL9.6The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ...
CVE-2021-21526MEDIUM6.7Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmi...
CVE-2021-30496MEDIUM5.7The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the...
CVE-2021-29155MEDIUM5.5An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds spe...
CVE-2021-28492MEDIUM4.9Unisys Stealth (core) 5.x before 5.0.048.0, 5.1.x before 5.1.017.0, and 6.x before 6.0.037.0 stores passwords in a recov...
CVE-2021-28156HIGH7.5HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fix...
CVE-2021-1079MEDIUM6.1NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugins where log files ar...
CVE-2021-28793CRITICAL9.8vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folde...
CVE-2021-25681HIGH7.5AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. T...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now