2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42577HIGH7.5An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client ...
CVE-2021-42262MEDIUM6.5An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the O...
CVE-2021-41850HIGH7.8An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroa...
CVE-2021-41849MEDIUM5.5An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Inform...
CVE-2021-41848HIGH7.8An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-...
CVE-2021-44667MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo param...
CVE-2021-33658HIGH7.8atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate...
CVE-2021-33150MEDIUM6.8Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an un...
CVE-2021-32478MEDIUM6.1The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect ...
CVE-2021-32477MEDIUM4.3The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with ...
CVE-2021-32476HIGH7.5A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodl...
CVE-2021-32475MEDIUM5.4ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10...
CVE-2021-32474HIGH7.2An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer hos...
CVE-2021-32473MEDIUM5.3It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.1...
CVE-2021-32472MEDIUM4.3Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle ve...
CVE-2021-32009MEDIUM6.1Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject java...
CVE-2021-27416MEDIUM5.4An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versio...
CVE-2021-27414MEDIUM6.1An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to an...
CVE-2021-26401MEDIUM5.6LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
CVE-2021-26341MEDIUM6.5Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage...
CVE-2021-23246HIGH7.5In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user i...
CVE-2021-44620CRITICAL9.8A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime para...
CVE-2021-44618CRITICAL9.8A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php...
CVE-2021-46708MEDIUM6.1The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the ...
CVE-2021-44597Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43857. Reason: This candidate is a reservation d...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now