2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27330 | MEDIUM | 6.1 | 6.2% | Feb 25, 2021 | Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read ... |
| CVE-2021-3124 | MEDIUM | 5.4 | 0.9% | Feb 25, 2021 | Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remot... |
| CVE-2021-3273 | HIGH | 7.2 | 5.6% | Feb 25, 2021 | Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this v... |
| CVE-2021-21066 | HIGH | 7.8 | 3.4% | Feb 25, 2021 | Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that ... |
| CVE-2021-21065 | HIGH | 7.8 | 3.4% | Feb 25, 2021 | Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that ... |
| CVE-2021-21064 | MEDIUM | 4.9 | 8.5% | Feb 25, 2021 | Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector... |
| CVE-2021-27671 | MEDIUM | 6.1 | 0.7% | Feb 25, 2021 | An issue was discovered in the comrak crate before 0.9.1 for Rust. XSS can occur because the protection mechanism for da... |
| CVE-2021-27670 | CRITICAL | 9.8 | 61.3% | Feb 25, 2021 | Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. |
| CVE-2021-1450 | MEDIUM | 5.5 | 0.2% | Feb 24, 2021 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow a... |
| CVE-2021-1396 | MEDIUM | 6.5 | 1.0% | Feb 24, 2021 | Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain pr... |
| CVE-2021-1393 | CRITICAL | 9.8 | 2.3% | Feb 24, 2021 | Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain pr... |
| CVE-2021-1388 | CRITICAL | 10 | 14.4% | Feb 24, 2021 | A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engi... |
| CVE-2021-1387 | HIGH | 8.6 | 1.4% | Feb 24, 2021 | A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a ... |
| CVE-2021-1368 | HIGH | 8.8 | 0.4% | Feb 24, 2021 | A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software coul... |
| CVE-2021-1367 | MEDIUM | 4.3 | 0.4% | Feb 24, 2021 | A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticat... |
| CVE-2021-1361 | CRITICAL | 9.1 | 1.6% | Feb 24, 2021 | A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Ci... |
| CVE-2021-1231 | MEDIUM | 4.7 | 0.2% | Feb 24, 2021 | A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric... |
| CVE-2021-1230 | HIGH | 7.5 | 1.5% | Feb 24, 2021 | A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centri... |
| CVE-2021-1229 | MEDIUM | 5.3 | 1.4% | Feb 24, 2021 | A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote att... |
| CVE-2021-1228 | MEDIUM | 6.5 | 0.4% | Feb 24, 2021 | A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in... |
| CVE-2021-1227 | HIGH | 8.1 | 0.7% | Feb 24, 2021 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct... |
| CVE-2021-22667 | CRITICAL | 9.8 | 3.6% | Feb 24, 2021 | BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an... |
| CVE-2021-21974 | HIGH | 8.8 | 45.1% | Feb 24, 2021 | OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG... |
| CVE-2021-21973 | MEDIUM | 5.3 | 88.0% | Feb 24, 2021 | The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR... |
| CVE-2021-21972 | CRITICAL | 9.8 | 99.5% | Feb 24, 2021 | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now