2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23838 | MEDIUM | 4.8 | 1.0% | Jan 15, 2021 | An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_fi... |
| CVE-2021-23837 | MEDIUM | 6.5 | 1.5% | Jan 15, 2021 | An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selec... |
| CVE-2021-23836 | MEDIUM | 4.8 | 0.9% | Jan 15, 2021 | An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_... |
| CVE-2021-23835 | MEDIUM | 4.9 | 1.7% | Jan 15, 2021 | An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the ... |
| CVE-2021-22132 | MEDIUM | 4.8 | 1.2% | Jan 14, 2021 | Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute... |
| CVE-2021-21261 | HIGH | 8.8 | 0.6% | Jan 14, 2021 | Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovere... |
| CVE-2021-21722 | MEDIUM | 4.4 | 0.4% | Jan 14, 2021 | A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers ... |
| CVE-2021-24122 | MEDIUM | 5.9 | 22.9% | Jan 14, 2021 | When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9... |
| CVE-2021-23926 | CRITICAL | 9.1 | 6.3% | Jan 14, 2021 | The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from maliciou... |
| CVE-2021-20618 | CRITICAL | 9.8 | 3.3% | Jan 14, 2021 | Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remot... |
| CVE-2021-20617 | CRITICAL | 9.8 | 7.9% | Jan 14, 2021 | Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows ... |
| CVE-2021-3138 | HIGH | 7.5 | 3.1% | Jan 14, 2021 | In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms. |
| CVE-2021-21013 | HIGH | 8.1 | 3.2% | Jan 13, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc... |
| CVE-2021-21012 | MEDIUM | 5.3 | 4.0% | Jan 13, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc... |
| CVE-2021-21011 | HIGH | 7 | 2.0% | Jan 13, 2021 | Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability t... |
| CVE-2021-21010 | HIGH | 7 | 2.5% | Jan 13, 2021 | InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could resu... |
| CVE-2021-21009 | HIGH | 8.6 | 3.2% | Jan 13, 2021 | Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier),... |
| CVE-2021-21008 | HIGH | 7 | 2.4% | Jan 13, 2021 | Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitra... |
| CVE-2021-21007 | HIGH | 7 | 2.2% | Jan 13, 2021 | Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arb... |
| CVE-2021-21006 | HIGH | 8.6 | 5.6% | Jan 13, 2021 | Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially... |
| CVE-2021-1360 | HIGH | 7.2 | 2.2% | Jan 13, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W... |
| CVE-2021-1311 | MEDIUM | 5.4 | 1.3% | Jan 13, 2021 | A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an ... |
| CVE-2021-1310 | MEDIUM | 4.7 | 1.6% | Jan 13, 2021 | A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote att... |
| CVE-2021-1307 | HIGH | 7.2 | 2.2% | Jan 13, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W... |
| CVE-2021-1267 | MEDIUM | 4.3 | 1.0% | Jan 13, 2021 | A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now