2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29760 | MEDIUM | 4.3 | 0.6% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unaut... |
| CVE-2021-29758 | MEDIUM | 4.3 | 0.6% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform action... |
| CVE-2021-39351 | MEDIUM | 6.5 | 1.1% | Oct 6, 2021 | The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Class... |
| CVE-2021-39350 | MEDIUM | 6.1 | 2.1% | Oct 6, 2021 | The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parame... |
| CVE-2021-0695 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to loc... |
| CVE-2021-0693 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due ... |
| CVE-2021-0691 | MEDIUM | 6.7 | 0.1% | Oct 6, 2021 | In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in othe... |
| CVE-2021-0690 | MEDIUM | 6.5 | 0.8% | Oct 6, 2021 | In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer ove... |
| CVE-2021-0689 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This... |
| CVE-2021-0687 | MEDIUM | 5 | 0.1% | Oct 6, 2021 | In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial o... |
| CVE-2021-0686 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app... |
| CVE-2021-0682 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to... |
| CVE-2021-0681 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l... |
| CVE-2021-0680 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l... |
| CVE-2021-0644 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identi... |
| CVE-2021-3848 | MEDIUM | 5.5 | 0.2% | Oct 6, 2021 | An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-F... |
| CVE-2021-36178 | MEDIUM | 6.5 | 0.6% | Oct 6, 2021 | A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose... |
| CVE-2021-36175 | MEDIUM | 5.4 | 0.6% | Oct 6, 2021 | An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below ... |
| CVE-2021-33602 | MEDIUM | 5.3 | 0.6% | Oct 6, 2021 | A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZ... |
| CVE-2021-24021 | MEDIUM | 5.4 | 0.6% | Oct 6, 2021 | An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below an... |
| CVE-2021-41122 | MEDIUM | 4.3 | 0.8% | Oct 5, 2021 | Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly valida... |
| CVE-2021-33849 | MEDIUM | 5.4 | 1.0% | Oct 5, 2021 | A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser i... |
| CVE-2021-31986 | MEDIUM | 6.8 | 0.8% | Oct 5, 2021 | User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow... |
| CVE-2021-3436 | MEDIUM | 6.5 | 0.9% | Oct 5, 2021 | BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known... |
| CVE-2021-41114 | MEDIUM | 5.3 | 1.2% | Oct 5, 2021 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now