2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-25464MEDIUM5.5An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.
CVE-2021-25462MEDIUM5.5NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory co...
CVE-2021-25460MEDIUM5.5An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta...
CVE-2021-25459MEDIUM5.5An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta...
CVE-2021-25458MEDIUM5.5NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory co...
CVE-2021-25456MEDIUM5.5OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy...
CVE-2021-25454MEDIUM5.5OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote...
CVE-2021-25453MEDIUM5.5Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluet...
CVE-2021-25452MEDIUM5.5An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows at...
CVE-2021-25450MEDIUM6.5Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file a...
CVE-2021-40284MEDIUM6.5D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of service. This vulnerabili...
CVE-2021-38725MEDIUM5.3Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php
CVE-2021-38721MEDIUM6.5FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability
CVE-2021-22239MEDIUM4.3An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
CVE-2021-37101MEDIUM6.8There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to im...
CVE-2021-28499MEDIUM5.5In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords...
CVE-2021-40223MEDIUM5.4Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configur...
CVE-2021-39458MEDIUM6.5Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS u...
CVE-2021-36871MEDIUM5.4Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plu...
CVE-2021-36870MEDIUM5.4Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (version...
CVE-2021-20118MEDIUM6.7Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an auth...
CVE-2021-20117MEDIUM6.7Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an auth...
CVE-2021-30294MEDIUM5.5Potential null pointer dereference in KGSL GPU auxiliary command due to improper validation of user input in Snapdragon ...
CVE-2021-1963MEDIUM6.7Possible use-after-free due to lack of validation for the rule count in filter table in IPA driver in Snapdragon Auto, S...
CVE-2021-1962MEDIUM6.7Buffer Overflow while processing IOCTL for getting peripheral endpoint information there is no proper validation for inp...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now