2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-25651HIGH7.8A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us...
CVE-2021-25650HIGH8.8A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us...
CVE-2021-35041HIGH7.5The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A mali...
CVE-2021-2322HIGH8.8Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior. Easily exploitable vulne...
CVE-2021-20019HIGH7.5A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this c...
CVE-2021-29620HIGH7.5Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML par...
CVE-2021-28976HIGH7.2Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
CVE-2021-31586HIGH8.8Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.
CVE-2021-21999HIGH7.8VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App...
CVE-2021-29087HIGH7.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2021-29086HIGH7.5Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Man...
CVE-2021-29085HIGH7.5Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file...
CVE-2021-29084HIGH7.5Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Secu...
CVE-2021-34372HIGH7.8Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol...
CVE-2021-32701HIGH7.5ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o...
CVE-2021-32700HIGH7.4Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2....
CVE-2021-22377HIGH7.2There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500...
CVE-2021-22363HIGH7.5There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specifi...
CVE-2021-22361HIGH7.8There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200,...
CVE-2021-34244HIGH8.8A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create n...
CVE-2021-0608HIGH7.8In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. Th...
CVE-2021-0607HIGH7.8In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missi...
CVE-2021-0553HIGH7.3In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI....
CVE-2021-0550HIGH7.8In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without use...
CVE-2021-0548HIGH7.8In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now