2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-34711MEDIUM5.5A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any f...
CVE-2021-34706MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2021-34702MEDIUM4.3A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2021-1534MEDIUM5.3A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)...
CVE-2021-41125MEDIUM6.5Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_u...
CVE-2021-25499MEDIUM5.5Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows att...
CVE-2021-25491MEDIUM4.4A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.
CVE-2021-25490MEDIUM6A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerabilit...
CVE-2021-25489MEDIUM5.5Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 ...
CVE-2021-25488MEDIUM5.5Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OO...
CVE-2021-25483MEDIUM6.5Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.
CVE-2021-25482MEDIUM4.4SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite...
CVE-2021-25481MEDIUM6.7An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass ...
CVE-2021-25477MEDIUM4.9An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote ...
CVE-2021-25476MEDIUM4.4An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass th...
CVE-2021-25475MEDIUM6.7A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrar...
CVE-2021-25474MEDIUM4.4Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI...
CVE-2021-25473MEDIUM4.4Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in Syst...
CVE-2021-25469MEDIUM6.7A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitra...
CVE-2021-25468MEDIUM4.4A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allo...
CVE-2021-25467MEDIUM6.7Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to S...
CVE-2021-29855MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnera...
CVE-2021-29836MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulner...
CVE-2021-29764MEDIUM5.4IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability all...
CVE-2021-29761MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensiti...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now