2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21699MEDIUM5.4Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic re...
CVE-2021-30266MEDIUM6.7Possible use after free due to improper memory validation when initializing new interface via Interface add command in S...
CVE-2021-30265MEDIUM6.7Possible memory corruption due to improper validation of memory address while processing user-space IOCTL for clearing F...
CVE-2021-30264MEDIUM6.7Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, ...
CVE-2021-1924MEDIUM5.5Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, ...
CVE-2021-1903MEDIUM5.3Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or...
CVE-2021-37910MEDIUM5.3ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerabi...
CVE-2021-34421MEDIUM4.3The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properl...
CVE-2021-34419MEDIUM5.3In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a re...
CVE-2021-34418MEDIUM5.3The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-P...
CVE-2021-3912MEDIUM6.5OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory...
CVE-2021-3911MEDIUM6.5If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
CVE-2021-33618MEDIUM6.1Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove at...
CVE-2021-42111MEDIUM5.5An issue was discovered in the RCDevs OpenOTP app 1.4.13 and 1.4.14 for iOS. If it is installed on a jailbroken device, ...
CVE-2021-3572MEDIUM5.7A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possi...
CVE-2021-32022MEDIUM5.5A low privileged delete vulnerability using CEF RPC server of BlackBerry Protect for Windows version(s) versions 1574 an...
CVE-2021-41038MEDIUM6.1In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via po...
CVE-2021-40517MEDIUM5.4Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the ...
CVE-2021-3380MEDIUM6.5Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive informati...
CVE-2021-42062MEDIUM4.3SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employe...
CVE-2021-41427MEDIUM6.1Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.
CVE-2021-40518MEDIUM6.5Airangel HSMX Gateway devices through 5.2.04 allow CSRF.
CVE-2021-40504MEDIUM4.9A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 71...
CVE-2021-43561MEDIUM5.4An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for...
CVE-2021-38887MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from applicatio...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now