2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39085CRITICAL9.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1...
CVE-2021-39035MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1...
CVE-2021-30490HIGH7.8upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binar...
CVE-2021-33236Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-34033. Reason: This candidate is a duplicate of ...
CVE-2021-33235Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-34035. Reason: This candidate is a duplicate of ...
CVE-2021-29118MEDIUM5.5An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) ...
CVE-2021-29117HIGH7.8A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an un...
CVE-2021-29112MEDIUM5.5An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) ...
CVE-2021-42751MEDIUM4.8A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat...
CVE-2021-42750MEDIUM4.8A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat...
CVE-2021-44720HIGH7.2In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source...
CVE-2021-22289CRITICAL9.8Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow...
CVE-2021-0975MEDIUM5.5In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side...
CVE-2021-0735MEDIUM5.5In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced i...
CVE-2021-0734MEDIUM5.5In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side cha...
CVE-2021-46778MEDIUM5.6Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenam...
CVE-2021-40040HIGH7.5Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulner...
CVE-2021-40034HIGH7.5The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of thi...
CVE-2021-40030HIGH7.5The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidential...
CVE-2021-39696HIGH7.8In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation ...
CVE-2021-33646HIGH7.5The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory ...
CVE-2021-33645HIGH7.5The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory ...
CVE-2021-33644HIGH8.1An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo...
CVE-2021-33643CRITICAL9.1An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo...
CVE-2021-46304HIGH7.5A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WI...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now