2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27017 | MEDIUM | 6.6 | 0.5% | Feb 7, 2025 | Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This ... |
| CVE-2021-3978 | MEDIUM | 5.5 | 0.1% | Jan 29, 2025 | When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set ... |
| CVE-2021-30745 | — | — | — | Jan 24, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Rejected Reason: This candidate is unused by its CNA. |
| CVE-2021-42718 | MEDIUM | 4.9 | 0.4% | Jan 23, 2025 | Information Disclosure in API in Replicated Replicated Classic versions prior to 2.53.1 on all platforms allows authenti... |
| CVE-2021-21158 | — | — | — | Jan 17, 2025 | Rejected reason: Further investigation determines issue is not within scope of this CNA |
| CVE-2021-0447 | — | — | — | Jan 17, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2021-0323 | — | — | — | Jan 17, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2021-35685 | — | — | — | Jan 16, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of ... |
| CVE-2021-35684 | — | — | — | Jan 16, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of ... |
| CVE-2021-29669 | MEDIUM | 5.4 | 0.2% | Jan 12, 2025 | IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allo... |
| CVE-2021-20455 | LOW | 3.7 | 0.5% | Jan 7, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive ... |
| CVE-2021-27285 | HIGH | 8.4 | 0.3% | Jan 6, 2025 | An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execut... |
| CVE-2021-37000 | HIGH | 7.8 | 0.1% | Dec 28, 2024 | Some Huawei wearables have a permission management vulnerability. |
| CVE-2021-22484 | HIGH | 7.5 | 0.3% | Dec 28, 2024 | Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful explo... |
| CVE-2021-40959 | MEDIUM | 6.1 | 0.2% | Dec 20, 2024 | A reflected cross-site scripting vulnerability in MONITORAPP Application Insight Web Application Firewall (AIWAF) <= 4.1... |
| CVE-2021-22501 | MEDIUM | 5.3 | 0.5% | Dec 19, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input ... |
| CVE-2021-26102 | CRITICAL | 9.1 | 16.4% | Dec 19, 2024 | A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remot... |
| CVE-2021-32589 | CRITICAL | 9.8 | 8.7% | Dec 19, 2024 | A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below... |
| CVE-2021-26115 | HIGH | 7.8 | 0.8% | Dec 19, 2024 | An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a lo... |
| CVE-2021-26093 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a loc... |
| CVE-2021-39081 | HIGH | 7.5 | 0.3% | Dec 19, 2024 | IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an at... |
| CVE-2021-29827 | MEDIUM | 5.2 | 0.3% | Dec 19, 2024 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By per... |
| CVE-2021-20553 | MEDIUM | 5.4 | 0.3% | Dec 19, 2024 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnera... |
| CVE-2021-26281 | MEDIUM | 5.5 | 0.2% | Dec 17, 2024 | Some parameters of the alarm clock module are improperly stored, leaking some sensitive information. |
| CVE-2021-26280 | HIGH | 7.9 | 0.1% | Dec 17, 2024 | Locally installed application can bypass the permission check and perform system operations that require permission. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now