2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21699 | MEDIUM | 5.4 | 88.5% | Nov 12, 2021 | Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic re... |
| CVE-2021-30266 | MEDIUM | 6.7 | 0.2% | Nov 12, 2021 | Possible use after free due to improper memory validation when initializing new interface via Interface add command in S... |
| CVE-2021-30265 | MEDIUM | 6.7 | 0.1% | Nov 12, 2021 | Possible memory corruption due to improper validation of memory address while processing user-space IOCTL for clearing F... |
| CVE-2021-30264 | MEDIUM | 6.7 | 0.1% | Nov 12, 2021 | Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, ... |
| CVE-2021-1924 | MEDIUM | 5.5 | 0.2% | Nov 12, 2021 | Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, ... |
| CVE-2021-1903 | MEDIUM | 5.3 | 0.5% | Nov 12, 2021 | Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or... |
| CVE-2021-37910 | MEDIUM | 5.3 | 2.4% | Nov 12, 2021 | ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerabi... |
| CVE-2021-34421 | MEDIUM | 4.3 | 0.7% | Nov 11, 2021 | The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properl... |
| CVE-2021-34419 | MEDIUM | 5.3 | 0.6% | Nov 11, 2021 | In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a re... |
| CVE-2021-34418 | MEDIUM | 5.3 | 0.6% | Nov 11, 2021 | The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-P... |
| CVE-2021-3912 | MEDIUM | 6.5 | 0.8% | Nov 11, 2021 | OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory... |
| CVE-2021-3911 | MEDIUM | 6.5 | 0.9% | Nov 11, 2021 | If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash. |
| CVE-2021-33618 | MEDIUM | 6.1 | 79.3% | Nov 10, 2021 | Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove at... |
| CVE-2021-42111 | MEDIUM | 5.5 | 0.2% | Nov 10, 2021 | An issue was discovered in the RCDevs OpenOTP app 1.4.13 and 1.4.14 for iOS. If it is installed on a jailbroken device, ... |
| CVE-2021-3572 | MEDIUM | 5.7 | 1.7% | Nov 10, 2021 | A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possi... |
| CVE-2021-32022 | MEDIUM | 5.5 | 0.3% | Nov 10, 2021 | A low privileged delete vulnerability using CEF RPC server of BlackBerry Protect for Windows version(s) versions 1574 an... |
| CVE-2021-41038 | MEDIUM | 6.1 | 0.7% | Nov 10, 2021 | In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via po... |
| CVE-2021-40517 | MEDIUM | 5.4 | 0.5% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the ... |
| CVE-2021-3380 | MEDIUM | 6.5 | 1.3% | Nov 10, 2021 | Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive informati... |
| CVE-2021-42062 | MEDIUM | 4.3 | 0.6% | Nov 10, 2021 | SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employe... |
| CVE-2021-41427 | MEDIUM | 6.1 | 1.0% | Nov 10, 2021 | Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi. |
| CVE-2021-40518 | MEDIUM | 6.5 | 0.4% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 allow CSRF. |
| CVE-2021-40504 | MEDIUM | 4.9 | 0.6% | Nov 10, 2021 | A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 71... |
| CVE-2021-43561 | MEDIUM | 5.4 | 0.5% | Nov 10, 2021 | An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for... |
| CVE-2021-38887 | MEDIUM | 6.5 | 0.8% | Nov 10, 2021 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from applicatio... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now