2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41021MEDIUM6.7A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may allow an admin user to...
CVE-2021-41013MEDIUM5.3An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Repo...
CVE-2021-36188MEDIUM6.1A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4....
CVE-2021-37093MEDIUM5.3There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may ...
CVE-2021-37039MEDIUM6.5There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may caus...
CVE-2021-25526MEDIUM5.5Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privi...
CVE-2021-25525MEDIUM6.5Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows...
CVE-2021-25520MEDIUM6.1Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16....
CVE-2021-25518MEDIUM6.7An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write ...
CVE-2021-25514MEDIUM6.5An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive inf...
CVE-2021-43063MEDIUM6.1A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4....
CVE-2021-36190MEDIUM6.3A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below al...
CVE-2021-43064MEDIUM6.1A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and b...
CVE-2021-41015MEDIUM6.1A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4....
CVE-2021-36191MEDIUM5.4A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below all...
CVE-2021-43067MEDIUM6.5A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2...
CVE-2021-42752MEDIUM5.4A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6....
CVE-2021-41029MEDIUM5.4A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6....
CVE-2021-32591MEDIUM5.3A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSan...
CVE-2021-4050MEDIUM6.1livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-42757MEDIUM6.7A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allo...
CVE-2021-31850MEDIUM6.1A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator ...
CVE-2021-44726MEDIUM6.1KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
CVE-2021-41309MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access...
CVE-2021-3370MEDIUM6.1DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now