2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25651 | HIGH | 7.8 | 0.5% | Jun 24, 2021 | A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us... |
| CVE-2021-25650 | HIGH | 8.8 | 0.5% | Jun 24, 2021 | A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us... |
| CVE-2021-35041 | HIGH | 7.5 | 1.3% | Jun 24, 2021 | The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A mali... |
| CVE-2021-2322 | HIGH | 8.8 | 1.4% | Jun 23, 2021 | Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior. Easily exploitable vulne... |
| CVE-2021-20019 | HIGH | 7.5 | 1.4% | Jun 23, 2021 | A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this c... |
| CVE-2021-29620 | HIGH | 7.5 | 2.2% | Jun 23, 2021 | Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML par... |
| CVE-2021-28976 | HIGH | 7.2 | 7.5% | Jun 23, 2021 | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess. |
| CVE-2021-31586 | HIGH | 8.8 | 44.1% | Jun 23, 2021 | Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. |
| CVE-2021-21999 | HIGH | 7.8 | 1.4% | Jun 23, 2021 | VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App... |
| CVE-2021-29087 | HIGH | 7.5 | 1.4% | Jun 23, 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2021-29086 | HIGH | 7.5 | 1.2% | Jun 23, 2021 | Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Man... |
| CVE-2021-29085 | HIGH | 7.5 | 1.3% | Jun 23, 2021 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file... |
| CVE-2021-29084 | HIGH | 7.5 | 1.3% | Jun 23, 2021 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Secu... |
| CVE-2021-34372 | HIGH | 7.8 | 0.3% | Jun 22, 2021 | Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol... |
| CVE-2021-32701 | HIGH | 7.5 | 1.3% | Jun 22, 2021 | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o... |
| CVE-2021-32700 | HIGH | 7.4 | 0.6% | Jun 22, 2021 | Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.... |
| CVE-2021-22377 | HIGH | 7.2 | 0.9% | Jun 22, 2021 | There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500... |
| CVE-2021-22363 | HIGH | 7.5 | 0.7% | Jun 22, 2021 | There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specifi... |
| CVE-2021-22361 | HIGH | 7.8 | 0.2% | Jun 22, 2021 | There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200,... |
| CVE-2021-34244 | HIGH | 8.8 | 0.6% | Jun 22, 2021 | A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create n... |
| CVE-2021-0608 | HIGH | 7.8 | 0.1% | Jun 22, 2021 | In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. Th... |
| CVE-2021-0607 | HIGH | 7.8 | 0.1% | Jun 22, 2021 | In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missi... |
| CVE-2021-0553 | HIGH | 7.3 | 0.1% | Jun 22, 2021 | In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI.... |
| CVE-2021-0550 | HIGH | 7.8 | 0.1% | Jun 22, 2021 | In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without use... |
| CVE-2021-0548 | HIGH | 7.8 | 0.1% | Jun 22, 2021 | In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now