2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45035MEDIUM5.9Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could al...
CVE-2021-3782MEDIUM6.6An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. Th...
CVE-2021-41803HIGH7.1HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to inte...
CVE-2021-27774MEDIUM5.4User input included in error response, which could be used in a phishing attack.
CVE-2021-39190MEDIUM5.3The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3...
CVE-2021-43310CRITICAL9.8A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys ...
CVE-2021-46835MEDIUM4.3There is a traffic hijacking vulnerability in WS7200-10 11.0.2.13. Successful exploitation of this vulnerability can cau...
CVE-2021-46834MEDIUM5.5A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resou...
CVE-2021-33081MEDIUM4.4Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially en...
CVE-2021-33079MEDIUM4.4Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially en...
CVE-2021-33076MEDIUM6.8Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially e...
CVE-2021-46836HIGH7.5Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of th...
CVE-2021-40024HIGH7.5Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of th...
CVE-2021-40023HIGH7.5Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality...
CVE-2021-40019CRITICAL9.1Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may caus...
CVE-2021-40017CRITICAL9.8The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may re...
CVE-2021-42597MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Storage Unit Rental Management System PHP 8.0.10 , A...
CVE-2021-41731MEDIUM4.8Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQ...
CVE-2021-42948LOW3.7HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links vi...
CVE-2021-42949CRITICAL9.8The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session to...
CVE-2021-44076MEDIUM4.8An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allow...
CVE-2021-38924HIGH7.5IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a det...
CVE-2021-36568MEDIUM5.4In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this cas...
CVE-2021-0943HIGH7.8In MMU_MapPages of TBD, there is a possible out of bounds write due to improper input validation. This could lead to loc...
CVE-2021-0942CRITICAL9.8The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the u...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now