2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22782MEDIUM5.5Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1...
CVE-2021-22781MEDIUM5.5Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1...
CVE-2021-33213MEDIUM6.5An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated u...
CVE-2021-33212MEDIUM5.4A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows r...
CVE-2021-33211MEDIUM6.5A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated...
CVE-2021-24117MEDIUM4.9In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (adm...
CVE-2021-0654MEDIUM5.5In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This cou...
CVE-2021-0604MEDIUM5.5In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files over Bluetooth due ...
CVE-2021-0601MEDIUM5.5In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free. This could lead to ...
CVE-2021-0599MEDIUM5.5In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadc...
CVE-2021-0597MEDIUM5.5In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names...
CVE-2021-0590MEDIUM4.4In sendNetworkConditionsBroadcast of NetworkMonitor.java, there is a possible way for a privileged app to receive WiFi B...
CVE-2021-0588MEDIUM5.5In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. ...
CVE-2021-0585MEDIUM6.7In beginWrite and beginRead of MessageQueueBase.h, there is a possible out of bounds write due to improper input validat...
CVE-2021-0518MEDIUM5.5In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to loca...
CVE-2021-0144MEDIUM6.7Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enabl...
CVE-2021-24119MEDIUM4.9In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (admin...
CVE-2021-24116MEDIUM4.9In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) a...
CVE-2021-33689MEDIUM4.3When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator app...
CVE-2021-33687MEDIUM4.9SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information i...
CVE-2021-33684MEDIUM5.3SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22...
CVE-2021-33683MEDIUM4.3SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC...
CVE-2021-33682MEDIUM5.4SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XS...
CVE-2021-33681MEDIUM6.5SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources...
CVE-2021-33680MEDIUM6.5SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now