2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27583MEDIUM5.3In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password r...
CVE-2021-26680HIGH7.2A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26679HIGH7.2A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26677HIGH7.8A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s):...
CVE-2021-26595MEDIUM5.3In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP versi...
CVE-2021-26594HIGH8.8In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any contr...
CVE-2021-26593HIGH7.5In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they g...
CVE-2021-22882HIGH7.5UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may ca...
CVE-2021-22112HIGH8.8Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported ...
CVE-2021-20247HIGH7.4A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not ...
CVE-2021-27582CRITICAL9.1org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect th...
CVE-2021-27579HIGH7.8Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed ...
CVE-2021-26926HIGH7.1A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to ...
CVE-2021-26686MEDIUM6.5A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior t...
CVE-2021-26684HIGH7.2A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26683HIGH7.2A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26682MEDIUM6.1A remote reflected cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s):...
CVE-2021-26681HIGH7.2A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26678MEDIUM6.1A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manage...
CVE-2021-22651HIGH7.8When loading a specially crafted file, Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10...
CVE-2021-20229MEDIUM4.3A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to c...
CVE-2021-20220MEDIUM4.8A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CV...
CVE-2021-20198HIGH8.1A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installat...
CVE-2021-26685MEDIUM6.5A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior t...
CVE-2021-22113MEDIUM5.3Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vul...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now