2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1399 | MEDIUM | 4.3 | 0.6% | Apr 8, 2021 | A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communica... |
| CVE-2021-1386 | HIGH | 7.8 | 0.3% | Apr 8, 2021 | A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpo... |
| CVE-2021-1380 | MEDIUM | 6.1 | 0.8% | Apr 8, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cis... |
| CVE-2021-1362 | HIGH | 8.8 | 2.7% | Apr 8, 2021 | A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager S... |
| CVE-2021-1309 | HIGH | 8.8 | 0.5% | Apr 8, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se... |
| CVE-2021-1308 | HIGH | 7.4 | 0.4% | Apr 8, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se... |
| CVE-2021-1251 | HIGH | 7.4 | 0.4% | Apr 8, 2021 | Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se... |
| CVE-2021-1137 | HIGH | 7.8 | 0.5% | Apr 8, 2021 | Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb... |
| CVE-2021-30457 | CRITICAL | 9.8 | 1.1% | Apr 7, 2021 | An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in remove_set upon a pa... |
| CVE-2021-30456 | CRITICAL | 9.8 | 1.1% | Apr 7, 2021 | An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in get_or_insert upon a... |
| CVE-2021-30455 | CRITICAL | 9.8 | 1.1% | Apr 7, 2021 | An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in IdMap::clone_from up... |
| CVE-2021-30454 | CRITICAL | 9.8 | 1.1% | Apr 7, 2021 | An issue was discovered in the outer_cgi crate before 0.2.1 for Rust. A user-provided Read instance receives an uninitia... |
| CVE-2021-29641 | HIGH | 8.8 | 4.9% | Apr 7, 2021 | Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions incl... |
| CVE-2021-30246 | CRITICAL | 9.1 | 1.0% | Apr 7, 2021 | In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized ... |
| CVE-2021-26758 | HIGH | 8.8 | 2.7% | Apr 7, 2021 | Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root term... |
| CVE-2021-30123 | HIGH | 8.8 | 3.4% | Apr 7, 2021 | FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code ... |
| CVE-2021-28166 | MEDIUM | 6.5 | 1.0% | Apr 7, 2021 | In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted C... |
| CVE-2021-21425 | CRITICAL | 9.8 | 80.5% | Apr 7, 2021 | Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versio... |
| CVE-2021-29627 | HIGH | 7.8 | 0.7% | Apr 7, 2021 | In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, liste... |
| CVE-2021-29626 | MEDIUM | 5.5 | 0.3% | Apr 7, 2021 | In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r369551, 11.4-STABLE before r369559, 13.0-RC5 before p1, 12.2-... |
| CVE-2021-28927 | HIGH | 7.8 | 1.5% | Apr 7, 2021 | The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platfor... |
| CVE-2021-30185 | HIGH | 7.5 | 1.0% | Apr 7, 2021 | CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link. |
| CVE-2021-21641 | MEDIUM | 4.3 | 1.2% | Apr 7, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to ... |
| CVE-2021-21640 | MEDIUM | 4.3 | 1.9% | Apr 7, 2021 | Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name... |
| CVE-2021-21639 | MEDIUM | 4.3 | 2.7% | Apr 7, 2021 | Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data s... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now