2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-1399MEDIUM4.3A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communica...
CVE-2021-1386HIGH7.8A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpo...
CVE-2021-1380MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cis...
CVE-2021-1362HIGH8.8A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager S...
CVE-2021-1309HIGH8.8Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se...
CVE-2021-1308HIGH7.4Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se...
CVE-2021-1251HIGH7.4Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se...
CVE-2021-1137HIGH7.8Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb...
CVE-2021-30457CRITICAL9.8An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in remove_set upon a pa...
CVE-2021-30456CRITICAL9.8An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in get_or_insert upon a...
CVE-2021-30455CRITICAL9.8An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in IdMap::clone_from up...
CVE-2021-30454CRITICAL9.8An issue was discovered in the outer_cgi crate before 0.2.1 for Rust. A user-provided Read instance receives an uninitia...
CVE-2021-29641HIGH8.8Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions incl...
CVE-2021-30246CRITICAL9.1In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized ...
CVE-2021-26758HIGH8.8Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root term...
CVE-2021-30123HIGH8.8FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code ...
CVE-2021-28166MEDIUM6.5In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted C...
CVE-2021-21425CRITICAL9.8Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versio...
CVE-2021-29627HIGH7.8In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, liste...
CVE-2021-29626MEDIUM5.5In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r369551, 11.4-STABLE before r369559, 13.0-RC5 before p1, 12.2-...
CVE-2021-28927HIGH7.8The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platfor...
CVE-2021-30185HIGH7.5CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.
CVE-2021-21641MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to ...
CVE-2021-21640MEDIUM4.3Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name...
CVE-2021-21639MEDIUM4.3Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data s...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now