2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20681 | MEDIUM | 5.4 | 0.7% | Mar 26, 2021 | Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remo... |
| CVE-2021-20677 | LOW | 3.1 | 0.9% | Mar 26, 2021 | UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 ... |
| CVE-2021-28250 | HIGH | 7.8 | 0.3% | Mar 26, 2021 | CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. W... |
| CVE-2021-28249 | HIGH | 8.8 | 0.4% | Mar 26, 2021 | CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Obje... |
| CVE-2021-28248 | HIGH | 7.5 | 1.4% | Mar 26, 2021 | CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts... |
| CVE-2021-28247 | MEDIUM | 5.4 | 0.7% | Mar 26, 2021 | CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticat... |
| CVE-2021-28246 | HIGH | 7.8 | 0.4% | Mar 26, 2021 | CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Obje... |
| CVE-2021-3153 | MEDIUM | 6.5 | 0.7% | Mar 26, 2021 | HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users withi... |
| CVE-2021-3027 | MEDIUM | 6.5 | 1.2% | Mar 26, 2021 | app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak t... |
| CVE-2021-3119 | HIGH | 7.5 | 1.6% | Mar 25, 2021 | Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sq... |
| CVE-2021-27372 | CRITICAL | 9.8 | 1.6% | Mar 25, 2021 | Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the dev... |
| CVE-2021-29098 | HIGH | 7.8 | 2.0% | Mar 25, 2021 | Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ... |
| CVE-2021-29097 | HIGH | 7.8 | 2.4% | Mar 25, 2021 | Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS... |
| CVE-2021-29095 | MEDIUM | 6.8 | 0.9% | Mar 25, 2021 | Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and e... |
| CVE-2021-29094 | MEDIUM | 6.8 | 1.0% | Mar 25, 2021 | Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier... |
| CVE-2021-29093 | MEDIUM | 6.8 | 0.9% | Mar 25, 2021 | A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows a... |
| CVE-2021-29010 | MEDIUM | 4.8 | 0.8% | Mar 25, 2021 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in th... |
| CVE-2021-29009 | MEDIUM | 4.8 | 0.8% | Mar 25, 2021 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in th... |
| CVE-2021-29008 | MEDIUM | 4.8 | 0.8% | Mar 25, 2021 | A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.p... |
| CVE-2021-27454 | HIGH | 7.8 | 0.2% | Mar 25, 2021 | The software performs an operation at a privilege level higher than the minimum level required, which creates new weakne... |
| CVE-2021-27452 | HIGH | 7.8 | 0.3% | Mar 25, 2021 | The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these... |
| CVE-2021-27450 | HIGH | 7.8 | 0.2% | Mar 25, 2021 | SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol... |
| CVE-2021-27448 | HIGH | 7.8 | 0.2% | Mar 25, 2021 | A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E ... |
| CVE-2021-27440 | CRITICAL | 9.8 | 1.4% | Mar 25, 2021 | The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to ... |
| CVE-2021-27438 | HIGH | 8.8 | 1.2% | Mar 25, 2021 | The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now