2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29760MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unaut...
CVE-2021-29758MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform action...
CVE-2021-39351MEDIUM6.5The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Class...
CVE-2021-39350MEDIUM6.1The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parame...
CVE-2021-0695MEDIUM5.5In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to loc...
CVE-2021-0693MEDIUM5.5In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due ...
CVE-2021-0691MEDIUM6.7In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in othe...
CVE-2021-0690MEDIUM6.5In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer ove...
CVE-2021-0689MEDIUM5.5In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This...
CVE-2021-0687MEDIUM5In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial o...
CVE-2021-0686MEDIUM5.5In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app...
CVE-2021-0682MEDIUM5.5In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to...
CVE-2021-0681MEDIUM5.5In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l...
CVE-2021-0680MEDIUM5.5In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l...
CVE-2021-0644MEDIUM5.5In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identi...
CVE-2021-3848MEDIUM5.5An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-F...
CVE-2021-36178MEDIUM6.5A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose...
CVE-2021-36175MEDIUM5.4An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below ...
CVE-2021-33602MEDIUM5.3A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZ...
CVE-2021-24021MEDIUM5.4An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below an...
CVE-2021-41122MEDIUM4.3Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly valida...
CVE-2021-33849MEDIUM5.4A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser i...
CVE-2021-31986MEDIUM6.8User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow...
CVE-2021-3436MEDIUM6.5BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known...
CVE-2021-41114MEDIUM5.3TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now