2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27876 | HIGH | 8.1 | 13.4% | Mar 1, 2021 | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc... |
| CVE-2021-26704 | HIGH | 8.8 | 3.1% | Mar 1, 2021 | EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/too... |
| CVE-2021-26703 | CRITICAL | 9.8 | 4.0% | Mar 1, 2021 | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input t... |
| CVE-2021-26702 | MEDIUM | 6.1 | 2.7% | Mar 1, 2021 | EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI. |
| CVE-2021-26476 | CRITICAL | 9.8 | 3.1% | Mar 1, 2021 | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI. |
| CVE-2021-26475 | MEDIUM | 6.1 | 6.1% | Mar 1, 2021 | EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI. |
| CVE-2021-3332 | MEDIUM | 5.3 | 1.8% | Mar 1, 2021 | WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password. |
| CVE-2021-27318 | MEDIUM | 6.1 | 1.5% | Mar 1, 2021 | Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to in... |
| CVE-2021-27317 | MEDIUM | 6.1 | 1.3% | Mar 1, 2021 | Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to in... |
| CVE-2021-21517 | HIGH | 7.2 | 1.4% | Mar 1, 2021 | SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML pa... |
| CVE-2021-21515 | MEDIUM | 5.4 | 0.8% | Mar 1, 2021 | Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privil... |
| CVE-2021-25914 | CRITICAL | 9.8 | 3.7% | Mar 1, 2021 | Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of... |
| CVE-2021-22114 | MEDIUM | 5.3 | 1.0% | Mar 1, 2021 | Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write... |
| CVE-2021-25833 | CRITICAL | 9.8 | 43.5% | Mar 1, 2021 | A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file ... |
| CVE-2021-25832 | CRITICAL | 9.8 | 12.6% | Mar 1, 2021 | A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentSer... |
| CVE-2021-25831 | CRITICAL | 9.8 | 11.5% | Mar 1, 2021 | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker mus... |
| CVE-2021-25830 | CRITICAL | 9.8 | 11.8% | Mar 1, 2021 | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacke... |
| CVE-2021-25829 | HIGH | 7.5 | 7.4% | Mar 1, 2021 | An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.... |
| CVE-2021-25329 | HIGH | 7 | 9.5% | Mar 1, 2021 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5... |
| CVE-2021-25122 | HIGH | 7.5 | 18.1% | Mar 1, 2021 | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0... |
| CVE-2021-27225 | MEDIUM | 5.4 | 0.5% | Mar 1, 2021 | In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have cod... |
| CVE-2021-27132 | CRITICAL | 9.8 | 16.7% | Feb 27, 2021 | SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via... |
| CVE-2021-3197 | CRITICAL | 9.8 | 72.3% | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by... |
| CVE-2021-3151 | MEDIUM | 5.4 | 1.2% | Feb 27, 2021 | i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attac... |
| CVE-2021-3148 | CRITICAL | 9.8 | 8.2% | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now