2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27891 | HIGH | 8.8 | 1.0% | Mar 15, 2021 | SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected. |
| CVE-2021-26924 | MEDIUM | 6.1 | 0.7% | Mar 15, 2021 | An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protecti... |
| CVE-2021-26923 | HIGH | 7.5 | 1.4% | Mar 15, 2021 | An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the ... |
| CVE-2021-27208 | MEDIUM | 6.8 | 0.4% | Mar 15, 2021 | When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when... |
| CVE-2021-20179 | HIGH | 8.1 | 1.2% | Mar 15, 2021 | A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corres... |
| CVE-2021-27576 | HIGH | 7.5 | 2.8% | Mar 15, 2021 | If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This is... |
| CVE-2021-28379 | HIGH | 8.8 | 6.0% | Mar 15, 2021 | web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow... |
| CVE-2021-28378 | MEDIUM | 5.4 | 8.8% | Mar 15, 2021 | Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations. |
| CVE-2021-28375 | HIGH | 7.8 | 0.3% | Mar 15, 2021 | An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not p... |
| CVE-2021-28374 | HIGH | 7.5 | 1.3% | Mar 15, 2021 | The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon ... |
| CVE-2021-28373 | HIGH | 7.5 | 0.9% | Mar 13, 2021 | The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code w... |
| CVE-2021-28361 | HIGH | 7.5 | 1.1% | Mar 13, 2021 | An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI tar... |
| CVE-2021-20018 | MEDIUM | 4.9 | 0.7% | Mar 13, 2021 | A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specif... |
| CVE-2021-20017 | HIGH | 8.8 | 1.8% | Mar 13, 2021 | A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS ... |
| CVE-2021-28162 | MEDIUM | 6.1 | 0.8% | Mar 12, 2021 | In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascr... |
| CVE-2021-28161 | MEDIUM | 6.1 | 0.7% | Mar 12, 2021 | In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javasc... |
| CVE-2021-28092 | HIGH | 7.5 | 2.2% | Mar 12, 2021 | The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression De... |
| CVE-2021-27290 | HIGH | 7.5 | 4.7% | Mar 12, 2021 | ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. ... |
| CVE-2021-21518 | HIGH | 7.8 | 0.3% | Mar 12, 2021 | Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business P... |
| CVE-2021-21726 | LOW | 2.3 | 0.4% | Mar 12, 2021 | Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient ver... |
| CVE-2021-21085 | HIGH | 7.8 | 3.7% | Mar 12, 2021 | Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An at... |
| CVE-2021-21082 | HIGH | 7.8 | 4.5% | Mar 12, 2021 | Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by a Memory Corruption vulnerability w... |
| CVE-2021-21080 | MEDIUM | 6.1 | 1.2% | Mar 12, 2021 | Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attac... |
| CVE-2021-21079 | MEDIUM | 6.1 | 1.1% | Mar 12, 2021 | Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attac... |
| CVE-2021-21078 | MEDIUM | 6.5 | 1.1% | Mar 12, 2021 | Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now