2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40004 | HIGH | 7.5 | 0.6% | Jan 10, 2022 | The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affe... |
| CVE-2021-40002 | HIGH | 8.8 | 0.4% | Jan 10, 2022 | The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result ... |
| CVE-2021-40000 | HIGH | 8.8 | 0.4% | Jan 10, 2022 | The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result ... |
| CVE-2021-39998 | HIGH | 7.5 | 0.7% | Jan 10, 2022 | There is Vulnerability of APIs being concurrently called for multiple times in HwConnectivityExService a in smartphones.... |
| CVE-2021-38990 | HIGH | 7.8 | 0.3% | Jan 10, 2022 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command w... |
| CVE-2021-38957 | HIGH | 7.5 | 1.0% | Jan 10, 2022 | IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validatio... |
| CVE-2021-38921 | HIGH | 7.5 | 0.7% | Jan 10, 2022 | IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow a... |
| CVE-2021-34087 | HIGH | 7.1 | 0.8% | Jan 10, 2022 | In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5... |
| CVE-2021-34086 | HIGH | 8.8 | 0.5% | Jan 10, 2022 | In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5... |
| CVE-2021-32998 | HIGH | 7.4 | 1.2% | Jan 10, 2022 | The FANUC R-30iA and R-30iB series controllers are vulnerable to an out-of-bounds write, which may allow an attacker to ... |
| CVE-2021-32996 | HIGH | 7.5 | 1.1% | Jan 10, 2022 | The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to cras... |
| CVE-2021-30360 | HIGH | 7.8 | 0.6% | Jan 10, 2022 | Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to ... |
| CVE-2021-20048 | HIGH | 8.8 | 1.9% | Jan 10, 2022 | A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to ca... |
| CVE-2021-20046 | HIGH | 8.8 | 1.9% | Jan 10, 2022 | A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker ... |
| CVE-2021-43045 | HIGH | 7.5 | 3.0% | Jan 6, 2022 | A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a... |
| CVE-2021-46079 | HIGH | 7.2 | 3.3% | Jan 6, 2022 | An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attac... |
| CVE-2021-46075 | HIGH | 7.2 | 2.6% | Jan 6, 2022 | A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users... |
| CVE-2021-46076 | HIGH | 8.8 | 3.3% | Jan 6, 2022 | Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious ph... |
| CVE-2021-45458 | HIGH | 7.5 | 2.1% | Jan 6, 2022 | Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the enc... |
| CVE-2021-45457 | HIGH | 7.5 | 2.3% | Jan 6, 2022 | In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apach... |
| CVE-2021-44878 | HIGH | 7.5 | 0.9% | Jan 6, 2022 | If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) d... |
| CVE-2021-27738 | HIGH | 7.5 | 2.6% | Jan 6, 2022 | All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API end... |
| CVE-2021-44564 | HIGH | 8.1 | 0.9% | Jan 6, 2022 | A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC de... |
| CVE-2021-44351 | HIGH | 7.5 | 1.8% | Jan 6, 2022 | An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter. |
| CVE-2021-46143 | HIGH | 7.8 | 3.8% | Jan 6, 2022 | In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now