2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35307 | MEDIUM | 6.5 | 1.0% | Aug 5, 2021 | An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Tes... |
| CVE-2021-35306 | MEDIUM | 6.5 | 1.0% | Aug 5, 2021 | An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the function AP4_StszAtom::Wr... |
| CVE-2021-33597 | MEDIUM | 5.5 | 0.5% | Aug 5, 2021 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F... |
| CVE-2021-33596 | MEDIUM | 4.1 | 0.8% | Aug 5, 2021 | Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe t... |
| CVE-2021-29975 | MEDIUM | 6.5 | 1.0% | Aug 5, 2021 | Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or format... |
| CVE-2021-29974 | MEDIUM | 4.3 | 0.8% | Aug 5, 2021 | When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would... |
| CVE-2021-29969 | MEDIUM | 5.9 | 1.2% | Aug 5, 2021 | If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses pri... |
| CVE-2021-25448 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in w... |
| CVE-2021-25447 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause l... |
| CVE-2021-25446 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause a... |
| CVE-2021-25445 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access int... |
| CVE-2021-25444 | MEDIUM | 5.5 | 0.8% | Aug 5, 2021 | An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileg... |
| CVE-2021-25443 | MEDIUM | 5.3 | 0.1% | Aug 5, 2021 | A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attac... |
| CVE-2021-22241 | MEDIUM | 5.4 | 1.0% | Aug 5, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a sto... |
| CVE-2021-22240 | MEDIUM | 4.3 | 0.7% | Aug 5, 2021 | Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on... |
| CVE-2021-21739 | MEDIUM | 4.6 | 0.2% | Aug 5, 2021 | A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficie... |
| CVE-2021-21738 | MEDIUM | 6.1 | 0.6% | Aug 5, 2021 | ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient inp... |
| CVE-2021-38138 | MEDIUM | 5.4 | 1.5% | Aug 5, 2021 | OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not a... |
| CVE-2021-32603 | MEDIUM | 6.5 | 0.7% | Aug 5, 2021 | A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and belo... |
| CVE-2021-32598 | MEDIUM | 4.3 | 0.8% | Aug 5, 2021 | An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager a... |
| CVE-2021-3539 | MEDIUM | 5.4 | 0.5% | Aug 4, 2021 | EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-... |
| CVE-2021-36805 | MEDIUM | 4.8 | 0.6% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the... |
| CVE-2021-36803 | MEDIUM | 5.4 | 0.6% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in pro... |
| CVE-2021-36802 | MEDIUM | 6.5 | 0.9% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'lo... |
| CVE-2021-38115 | MEDIUM | 6.5 | 1.9% | Aug 4, 2021 | read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a deni... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now