2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3142 | — | — | — | Jan 28, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35128. Reason: This candidate is a reservation d... |
| CVE-2021-26067 | MEDIUM | 5.3 | 1.1% | Jan 28, 2021 | Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the... |
| CVE-2021-3331 | CRITICAL | 9.8 | 7.4% | Jan 27, 2021 | WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted UR... |
| CVE-2021-3326 | HIGH | 7.5 | 3.1% | Jan 27, 2021 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences i... |
| CVE-2021-26276 | MEDIUM | 5.3 | 1.2% | Jan 27, 2021 | scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when pr... |
| CVE-2021-22655 | HIGH | 7.8 | 1.2% | Jan 27, 2021 | Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an ... |
| CVE-2021-22653 | HIGH | 7.8 | 1.2% | Jan 27, 2021 | Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an... |
| CVE-2021-22641 | HIGH | 7.8 | 2.1% | Jan 27, 2021 | A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an a... |
| CVE-2021-22639 | HIGH | 7.8 | 1.9% | Jan 27, 2021 | An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attac... |
| CVE-2021-22637 | HIGH | 7.8 | 2.1% | Jan 27, 2021 | Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, all... |
| CVE-2021-3325 | CRITICAL | 9.8 | 2.2% | Jan 27, 2021 | Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation... |
| CVE-2021-26118 | HIGH | 7.5 | 4.0% | Jan 27, 2021 | While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Ap... |
| CVE-2021-26117 | HIGH | 7.5 | 11.2% | Jan 27, 2021 | The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for ... |
| CVE-2021-25247 | HIGH | 7.8 | 0.7% | Jan 27, 2021 | A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker... |
| CVE-2021-25226 | MEDIUM | 5.5 | 0.4% | Jan 27, 2021 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci... |
| CVE-2021-25225 | MEDIUM | 5.5 | 0.4% | Jan 27, 2021 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci... |
| CVE-2021-25224 | MEDIUM | 5.5 | 0.4% | Jan 27, 2021 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci... |
| CVE-2021-3318 | MEDIUM | 6.1 | 2.8% | Jan 27, 2021 | attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter. |
| CVE-2021-20357 | MEDIUM | 5.4 | 0.7% | Jan 27, 2021 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2021-25312 | HIGH | 8.8 | 1.0% | Jan 27, 2021 | HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS au... |
| CVE-2021-25311 | CRITICAL | 9.9 | 3.2% | Jan 27, 2021 | condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, ... |
| CVE-2021-3272 | MEDIUM | 5.5 | 1.1% | Jan 27, 2021 | jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid rel... |
| CVE-2021-3317 | HIGH | 8.8 | 41.4% | Jan 26, 2021 | KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of ... |
| CVE-2021-3165 | HIGH | 8.8 | 2.2% | Jan 26, 2021 | SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI. |
| CVE-2021-1071 | MEDIUM | 5.5 | 0.3% | Jan 26, 2021 | NVIDIA Tegra kernel in Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, all L4T versions prior t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now