2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36324 | MEDIUM | 6.7 | 0.2% | Nov 12, 2021 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2021-36323 | MEDIUM | 6.7 | 0.2% | Nov 12, 2021 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2021-36315 | MEDIUM | 6.8 | 0.2% | Nov 12, 2021 | Dell EMC PowerScale Nodes contain a hardware design flaw. This may allow a local unauthenticated user to escalate privil... |
| CVE-2021-36305 | MEDIUM | 6.5 | 0.8% | Nov 12, 2021 | Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An... |
| CVE-2021-3843 | MEDIUM | 6.7 | 0.3% | Nov 12, 2021 | A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local ... |
| CVE-2021-3793 | MEDIUM | 5.3 | 0.7% | Nov 12, 2021 | An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow... |
| CVE-2021-3792 | MEDIUM | 5.3 | 0.5% | Nov 12, 2021 | Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypt... |
| CVE-2021-3791 | MEDIUM | 6.5 | 0.4% | Nov 12, 2021 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow a... |
| CVE-2021-3790 | MEDIUM | 6.5 | 0.4% | Nov 12, 2021 | A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow... |
| CVE-2021-3789 | MEDIUM | 4.6 | 0.1% | Nov 12, 2021 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow a... |
| CVE-2021-3788 | MEDIUM | 6.8 | 0.2% | Nov 12, 2021 | An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker wi... |
| CVE-2021-3786 | MEDIUM | 5.5 | 0.2% | Nov 12, 2021 | A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad s... |
| CVE-2021-3720 | MEDIUM | 5.5 | 0.2% | Nov 12, 2021 | An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and ... |
| CVE-2021-3719 | MEDIUM | 6.7 | 0.2% | Nov 12, 2021 | A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from ... |
| CVE-2021-3718 | MEDIUM | 4.6 | 0.2% | Nov 12, 2021 | A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhan... |
| CVE-2021-3599 | MEDIUM | 6.7 | 0.3% | Nov 12, 2021 | A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an ... |
| CVE-2021-3519 | MEDIUM | 6.8 | 0.2% | Nov 12, 2021 | A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when t... |
| CVE-2021-43332 | MEDIUM | 6.5 | 1.1% | Nov 12, 2021 | In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the li... |
| CVE-2021-43331 | MEDIUM | 6.1 | 1.3% | Nov 12, 2021 | In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for... |
| CVE-2021-41972 | MEDIUM | 6.5 | 1.4% | Nov 12, 2021 | Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This i... |
| CVE-2021-38985 | MEDIUM | 4.3 | 0.6% | Nov 12, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectl... |
| CVE-2021-38972 | MEDIUM | 4.3 | 0.6% | Nov 12, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectl... |
| CVE-2021-43576 | MEDIUM | 6.5 | 2.4% | Nov 12, 2021 | Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks... |
| CVE-2021-21701 | MEDIUM | 6.5 | 1.7% | Nov 12, 2021 | Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attac... |
| CVE-2021-21700 | MEDIUM | 5.4 | 0.7% | Nov 12, 2021 | Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their dele... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now