2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-35307MEDIUM6.5An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Tes...
CVE-2021-35306MEDIUM6.5An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the function AP4_StszAtom::Wr...
CVE-2021-33597MEDIUM5.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F...
CVE-2021-33596MEDIUM4.1Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe t...
CVE-2021-29975MEDIUM6.5Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or format...
CVE-2021-29974MEDIUM4.3When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would...
CVE-2021-29969MEDIUM5.9If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses pri...
CVE-2021-25448MEDIUM5.3Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in w...
CVE-2021-25447MEDIUM5.3Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause l...
CVE-2021-25446MEDIUM5.3Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause a...
CVE-2021-25445MEDIUM5.3Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access int...
CVE-2021-25444MEDIUM5.5An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileg...
CVE-2021-25443MEDIUM5.3A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attac...
CVE-2021-22241MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a sto...
CVE-2021-22240MEDIUM4.3Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on...
CVE-2021-21739MEDIUM4.6A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficie...
CVE-2021-21738MEDIUM6.1ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient inp...
CVE-2021-38138MEDIUM5.4OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not a...
CVE-2021-32603MEDIUM6.5A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and belo...
CVE-2021-32598MEDIUM4.3An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager a...
CVE-2021-3539MEDIUM5.4EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-...
CVE-2021-36805MEDIUM4.8Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the...
CVE-2021-36803MEDIUM5.4Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in pro...
CVE-2021-36802MEDIUM6.5Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'lo...
CVE-2021-38115MEDIUM6.5read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a deni...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now