2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29998 | CRITICAL | 9.8 | 2.4% | Apr 13, 2021 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. |
| CVE-2021-29997 | MEDIUM | 5.3 | 1.0% | Apr 13, 2021 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on... |
| CVE-2021-28973 | MEDIUM | 4.9 | 0.9% | Apr 13, 2021 | The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input dat... |
| CVE-2021-21731 | HIGH | 8.1 | 0.4% | Apr 13, 2021 | A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management p... |
| CVE-2021-21730 | CRITICAL | 9.8 | 1.0% | Apr 13, 2021 | A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to acc... |
| CVE-2021-21729 | MEDIUM | 6.5 | 0.4% | Apr 13, 2021 | Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perfo... |
| CVE-2021-30176 | CRITICAL | 9.8 | 29.0% | Apr 13, 2021 | The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/dev... |
| CVE-2021-30175 | CRITICAL | 9.8 | 8.5% | Apr 13, 2021 | ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page. |
| CVE-2021-28421 | — | — | — | Apr 13, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-21417. Reason: This candidate is a duplicate of ... |
| CVE-2021-22505 | CRITICAL | 9.8 | 1.5% | Apr 13, 2021 | Escalation of privileges vulnerability in Micro Focus Operations Agent, affects versions 12.0x, 12.10, 12.11, 12.12, 12.... |
| CVE-2021-28647 | HIGH | 7.8 | 0.5% | Apr 13, 2021 | Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an at... |
| CVE-2021-28646 | MEDIUM | 5.5 | 0.4% | Apr 13, 2021 | An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could al... |
| CVE-2021-28645 | HIGH | 7.8 | 0.5% | Apr 13, 2021 | An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 co... |
| CVE-2021-25253 | HIGH | 7.8 | 1.9% | Apr 13, 2021 | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP... |
| CVE-2021-25250 | HIGH | 7.8 | 0.5% | Apr 13, 2021 | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP... |
| CVE-2021-29943 | CRITICAL | 9.1 | 5.3% | Apr 13, 2021 | When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/p... |
| CVE-2021-29425 | MEDIUM | 4.8 | 10.2% | Apr 13, 2021 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "/... |
| CVE-2021-29262 | HIGH | 7.5 | 7.8% | Apr 13, 2021 | When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigest... |
| CVE-2021-27905 | CRITICAL | 9.8 | 93.1% | Apr 13, 2021 | The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also ... |
| CVE-2021-29054 | HIGH | 8.8 | 0.8% | Apr 13, 2021 | Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS... |
| CVE-2021-29003 | CRITICAL | 9.8 | 45.4% | Apr 13, 2021 | Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter... |
| CVE-2021-28938 | MEDIUM | 4.3 | 0.8% | Apr 13, 2021 | Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10.... |
| CVE-2021-30637 | MEDIUM | 5.4 | 1.9% | Apr 13, 2021 | htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php. |
| CVE-2021-30503 | CRITICAL | 9.8 | 2.9% | Apr 13, 2021 | The unofficial GLSL Linting extension before 1.4.0 for Visual Studio Code allows remote code execution via a crafted gls... |
| CVE-2021-30044 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now