2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23341 | HIGH | 7.5 | 3.2% | Feb 18, 2021 | The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc,... |
| CVE-2021-23340 | HIGH | 7.1 | 1.3% | Feb 18, 2021 | This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAct... |
| CVE-2021-20446 | MEDIUM | 5.4 | 0.5% | Feb 18, 2021 | IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2021-20445 | MEDIUM | 6.5 | 1.1% | Feb 18, 2021 | IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of... |
| CVE-2021-20444 | MEDIUM | 6.1 | 0.7% | Feb 18, 2021 | IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2021-20443 | HIGH | 8.8 | 0.8% | Feb 18, 2021 | IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is ou... |
| CVE-2021-20354 | HIGH | 7.5 | 3.7% | Feb 18, 2021 | IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker co... |
| CVE-2021-27378 | CRITICAL | 9.8 | 1.2% | Feb 18, 2021 | An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle ... |
| CVE-2021-27377 | CRITICAL | 9.8 | 1.3% | Feb 18, 2021 | An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_n... |
| CVE-2021-27376 | CRITICAL | 9.8 | 1.4% | Feb 18, 2021 | An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain ver... |
| CVE-2021-27124 | MEDIUM | 6.5 | 5.7% | Feb 18, 2021 | SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated ... |
| CVE-2021-27375 | MEDIUM | 5.3 | 0.8% | Feb 18, 2021 | Traefik before 2.4.5 allows the loading of IFRAME elements from other domains. |
| CVE-2021-27138 | HIGH | 7.8 | 1.1% | Feb 17, 2021 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT. |
| CVE-2021-27097 | HIGH | 7.8 | 1.0% | Feb 17, 2021 | The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT. |
| CVE-2021-27374 | HIGH | 7.5 | 1.1% | Feb 17, 2021 | VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff ... |
| CVE-2021-26720 | HIGH | 7.8 | 0.4% | Feb 17, 2021 | avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-d... |
| CVE-2021-3396 | HIGH | 8.8 | 2.4% | Feb 17, 2021 | OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through... |
| CVE-2021-27367 | HIGH | 7.5 | 1.7% | Feb 17, 2021 | Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow D... |
| CVE-2021-26911 | HIGH | 7.4 | 1.1% | Feb 17, 2021 | core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode. |
| CVE-2021-1416 | MEDIUM | 4.3 | 0.9% | Feb 17, 2021 | Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot... |
| CVE-2021-1412 | MEDIUM | 6.5 | 1.0% | Feb 17, 2021 | Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot... |
| CVE-2021-1378 | HIGH | 7.5 | 1.5% | Feb 17, 2021 | A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker ... |
| CVE-2021-1372 | MEDIUM | 5.5 | 0.4% | Feb 17, 2021 | A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticate... |
| CVE-2021-1366 | HIGH | 7.8 | 1.3% | Feb 17, 2021 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c... |
| CVE-2021-1351 | MEDIUM | 6.1 | 0.8% | Feb 17, 2021 | A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to co... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now