2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27583 | MEDIUM | 5.3 | 1.1% | Feb 23, 2021 | In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password r... |
| CVE-2021-26680 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26679 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26677 | HIGH | 7.8 | 0.3% | Feb 23, 2021 | A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s):... |
| CVE-2021-26595 | MEDIUM | 5.3 | 0.7% | Feb 23, 2021 | In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP versi... |
| CVE-2021-26594 | HIGH | 8.8 | 1.2% | Feb 23, 2021 | In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any contr... |
| CVE-2021-26593 | HIGH | 7.5 | 1.4% | Feb 23, 2021 | In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they g... |
| CVE-2021-22882 | HIGH | 7.5 | 1.3% | Feb 23, 2021 | UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may ca... |
| CVE-2021-22112 | HIGH | 8.8 | 3.2% | Feb 23, 2021 | Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported ... |
| CVE-2021-20247 | HIGH | 7.4 | 1.9% | Feb 23, 2021 | A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not ... |
| CVE-2021-27582 | CRITICAL | 9.1 | 2.2% | Feb 23, 2021 | org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect th... |
| CVE-2021-27579 | HIGH | 7.8 | 0.5% | Feb 23, 2021 | Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed ... |
| CVE-2021-26926 | HIGH | 7.1 | 1.2% | Feb 23, 2021 | A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to ... |
| CVE-2021-26686 | MEDIUM | 6.5 | 1.2% | Feb 23, 2021 | A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior t... |
| CVE-2021-26684 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26683 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26682 | MEDIUM | 6.1 | 0.8% | Feb 23, 2021 | A remote reflected cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s):... |
| CVE-2021-26681 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26678 | MEDIUM | 6.1 | 0.9% | Feb 23, 2021 | A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manage... |
| CVE-2021-22651 | HIGH | 7.8 | 2.6% | Feb 23, 2021 | When loading a specially crafted file, Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10... |
| CVE-2021-20229 | MEDIUM | 4.3 | 1.5% | Feb 23, 2021 | A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to c... |
| CVE-2021-20220 | MEDIUM | 4.8 | 1.1% | Feb 23, 2021 | A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CV... |
| CVE-2021-20198 | HIGH | 8.1 | 1.8% | Feb 23, 2021 | A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installat... |
| CVE-2021-26685 | MEDIUM | 6.5 | 1.1% | Feb 23, 2021 | A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior t... |
| CVE-2021-22113 | MEDIUM | 5.3 | 0.8% | Feb 23, 2021 | Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vul... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now