2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-20461MEDIUM6.5IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configura...
CVE-2021-20107MEDIUM5.4There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and...
CVE-2021-35956MEDIUM5.4Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut...
CVE-2021-27902MEDIUM6.1An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in conne...
CVE-2021-34385MEDIUM6.7Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calculation of a length co...
CVE-2021-34383MEDIUM6.7Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or esc...
CVE-2021-34379MEDIUM6.7Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an ...
CVE-2021-34378MEDIUM6.7Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restrict...
CVE-2021-34377MEDIUM6.7Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restricti...
CVE-2021-34376MEDIUM6.7Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restricti...
CVE-2021-34375MEDIUM6.7Trusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might...
CVE-2021-34374MEDIUM6.7Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerabilit...
CVE-2021-34373MEDIUM6Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could...
CVE-2021-31721MEDIUM6.1Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.
CVE-2021-28693MEDIUM5.5xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary ...
CVE-2021-35959MEDIUM5.4In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a fo...
CVE-2021-22341MEDIUM4.9There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers wi...
CVE-2021-22329MEDIUM4.9There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform s...
CVE-2021-32721MEDIUM6.1PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to ...
CVE-2021-22340MEDIUM4.1There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O r...
CVE-2021-22338MEDIUM5.3There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict ope...
CVE-2021-20079MEDIUM6.7Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus...
CVE-2021-20580MEDIUM4.3IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to exe...
CVE-2021-20490MEDIUM5.5IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure fi...
CVE-2021-20477MEDIUM5.4IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now