2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22782 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1... |
| CVE-2021-22781 | MEDIUM | 5.5 | 0.2% | Jul 14, 2021 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1... |
| CVE-2021-33213 | MEDIUM | 6.5 | 1.3% | Jul 14, 2021 | An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated u... |
| CVE-2021-33212 | MEDIUM | 5.4 | 0.7% | Jul 14, 2021 | A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows r... |
| CVE-2021-33211 | MEDIUM | 6.5 | 1.7% | Jul 14, 2021 | A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated... |
| CVE-2021-24117 | MEDIUM | 4.9 | 2.2% | Jul 14, 2021 | In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (adm... |
| CVE-2021-0654 | MEDIUM | 5.5 | 0.3% | Jul 14, 2021 | In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This cou... |
| CVE-2021-0604 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files over Bluetooth due ... |
| CVE-2021-0601 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free. This could lead to ... |
| CVE-2021-0599 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadc... |
| CVE-2021-0597 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names... |
| CVE-2021-0590 | MEDIUM | 4.4 | 0.1% | Jul 14, 2021 | In sendNetworkConditionsBroadcast of NetworkMonitor.java, there is a possible way for a privileged app to receive WiFi B... |
| CVE-2021-0588 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. ... |
| CVE-2021-0585 | MEDIUM | 6.7 | 0.1% | Jul 14, 2021 | In beginWrite and beginRead of MessageQueueBase.h, there is a possible out of bounds write due to improper input validat... |
| CVE-2021-0518 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to loca... |
| CVE-2021-0144 | MEDIUM | 6.7 | 0.3% | Jul 14, 2021 | Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enabl... |
| CVE-2021-24119 | MEDIUM | 4.9 | 1.4% | Jul 14, 2021 | In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (admin... |
| CVE-2021-24116 | MEDIUM | 4.9 | 1.0% | Jul 14, 2021 | In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) a... |
| CVE-2021-33689 | MEDIUM | 4.3 | 0.5% | Jul 14, 2021 | When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator app... |
| CVE-2021-33687 | MEDIUM | 4.9 | 1.6% | Jul 14, 2021 | SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information i... |
| CVE-2021-33684 | MEDIUM | 5.3 | 1.2% | Jul 14, 2021 | SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22... |
| CVE-2021-33683 | MEDIUM | 4.3 | 0.5% | Jul 14, 2021 | SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC... |
| CVE-2021-33682 | MEDIUM | 5.4 | 0.6% | Jul 14, 2021 | SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XS... |
| CVE-2021-33681 | MEDIUM | 6.5 | 0.8% | Jul 14, 2021 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources... |
| CVE-2021-33680 | MEDIUM | 6.5 | 0.8% | Jul 14, 2021 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now