2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41021 | MEDIUM | 6.7 | 0.3% | Dec 8, 2021 | A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may allow an admin user to... |
| CVE-2021-41013 | MEDIUM | 5.3 | 0.9% | Dec 8, 2021 | An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Repo... |
| CVE-2021-36188 | MEDIUM | 6.1 | 0.7% | Dec 8, 2021 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.... |
| CVE-2021-37093 | MEDIUM | 5.3 | 0.5% | Dec 8, 2021 | There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may ... |
| CVE-2021-37039 | MEDIUM | 6.5 | 0.3% | Dec 8, 2021 | There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may caus... |
| CVE-2021-25526 | MEDIUM | 5.5 | 0.2% | Dec 8, 2021 | Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privi... |
| CVE-2021-25525 | MEDIUM | 6.5 | 0.3% | Dec 8, 2021 | Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows... |
| CVE-2021-25520 | MEDIUM | 6.1 | 0.4% | Dec 8, 2021 | Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.... |
| CVE-2021-25518 | MEDIUM | 6.7 | 0.1% | Dec 8, 2021 | An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write ... |
| CVE-2021-25514 | MEDIUM | 6.5 | 0.2% | Dec 8, 2021 | An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive inf... |
| CVE-2021-43063 | MEDIUM | 6.1 | 0.9% | Dec 8, 2021 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.... |
| CVE-2021-36190 | MEDIUM | 6.3 | 0.8% | Dec 8, 2021 | A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below al... |
| CVE-2021-43064 | MEDIUM | 6.1 | 0.6% | Dec 8, 2021 | A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and b... |
| CVE-2021-41015 | MEDIUM | 6.1 | 0.8% | Dec 8, 2021 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.... |
| CVE-2021-36191 | MEDIUM | 5.4 | 0.5% | Dec 8, 2021 | A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below all... |
| CVE-2021-43067 | MEDIUM | 6.5 | 1.1% | Dec 8, 2021 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2... |
| CVE-2021-42752 | MEDIUM | 5.4 | 0.5% | Dec 8, 2021 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.... |
| CVE-2021-41029 | MEDIUM | 5.4 | 0.5% | Dec 8, 2021 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.... |
| CVE-2021-32591 | MEDIUM | 5.3 | 0.9% | Dec 8, 2021 | A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSan... |
| CVE-2021-4050 | MEDIUM | 6.1 | 0.9% | Dec 8, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-42757 | MEDIUM | 6.7 | 0.5% | Dec 8, 2021 | A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allo... |
| CVE-2021-31850 | MEDIUM | 6.1 | 1.0% | Dec 8, 2021 | A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator ... |
| CVE-2021-44726 | MEDIUM | 6.1 | 0.7% | Dec 8, 2021 | KNIME Server before 4.13.4 allows XSS via the old WebPortal login page. |
| CVE-2021-41309 | MEDIUM | 5.3 | 0.8% | Dec 8, 2021 | Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access... |
| CVE-2021-3370 | MEDIUM | 6.1 | 0.6% | Dec 8, 2021 | DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now