2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22141MEDIUM6.1An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously cr...
CVE-2021-36905MEDIUM5.4Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3....
CVE-2021-31608MEDIUM4.3Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.
CVE-2021-33897MEDIUM5.5A buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to caus...
CVE-2021-38819HIGH8.8A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the alb...
CVE-2021-4241MEDIUM5.3A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedI...
CVE-2021-4240MEDIUM5.3A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePassw...
CVE-2021-40272MEDIUM6.1OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).
CVE-2021-38828MEDIUM5.3Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.
CVE-2021-38827HIGH7.5Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover.
CVE-2021-33164MEDIUM6.7Improper access control in BIOS firmware for some Intel(R) NUCs before version INWHL357.0046 may allow a privileged user...
CVE-2021-33159MEDIUM6.7Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15....
CVE-2021-33064HIGH7.8Uncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticat...
CVE-2021-26251MEDIUM6.5Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potent...
CVE-2021-0185MEDIUM6.7Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a ...
CVE-2021-40289MEDIUM6.1mm-wki v0.2.1 is vulnerable to Cross Site Scripting (XSS).
CVE-2021-40226HIGH7.5xpdfreader 4.03 is vulnerable to Buffer Overflow.
CVE-2021-46852HIGH7.5The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affec...
CVE-2021-46851CRITICAL9.8The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerabil...
CVE-2021-26393MEDIUM5.5Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authentic...
CVE-2021-26392HIGH7.8Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing ...
CVE-2021-26391HIGH7.8Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker w...
CVE-2021-26360HIGH7.8An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC...
CVE-2021-34579HIGH7.5In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of th...
CVE-2021-34577MEDIUM6.5In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded sh...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now