2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-22376HIGH8.4A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnera...
CVE-2021-22372HIGH7.5There is a Security Features Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affec...
CVE-2021-22370HIGH7.5There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerabili...
CVE-2021-22326HIGH7.1A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this ...
CVE-2021-28993HIGH7.5Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).
CVE-2021-25951HIGH7.5XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
CVE-2021-34384HIGH7.8Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which m...
CVE-2021-34382HIGH7.8Trusty TLK contains a vulnerability in the NVIDIA TLK kernel’s tz_map_shared_mem function where an integer overflow on t...
CVE-2021-34381HIGH7.8Trusty TLK contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of ...
CVE-2021-34380HIGH7.8Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metad...
CVE-2021-28692HIGH7.1inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operati...
CVE-2021-25321HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Man...
CVE-2021-32567HIGH7.5Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This is...
CVE-2021-32566HIGH7.5Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This is...
CVE-2021-35941HIGH7.5Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that ca...
CVE-2021-29485HIGH8.8Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote ...
CVE-2021-29481HIGH7.5Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side...
CVE-2021-22439HIGH8.1There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request t...
CVE-2021-28830HIGH7.8The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtim...
CVE-2021-23275HIGH7.8The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enter...
CVE-2021-22119HIGH7.5Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are...
CVE-2021-21871HIGH7.8A memory corruption vulnerability exists in the DMG File Format Handler functionality of PowerISO 7.9. A specially craft...
CVE-2021-20104HIGH8.1Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of ...
CVE-2021-20102HIGH8.8Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.
CVE-2021-31516HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vector 35 Binary Ninja...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now