2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20461 | MEDIUM | 6.5 | 1.0% | Jun 30, 2021 | IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configura... |
| CVE-2021-20107 | MEDIUM | 5.4 | 0.5% | Jun 30, 2021 | There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and... |
| CVE-2021-35956 | MEDIUM | 5.4 | 3.2% | Jun 30, 2021 | Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut... |
| CVE-2021-27902 | MEDIUM | 6.1 | 1.0% | Jun 30, 2021 | An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in conne... |
| CVE-2021-34385 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calculation of a length co... |
| CVE-2021-34383 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or esc... |
| CVE-2021-34379 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an ... |
| CVE-2021-34378 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restrict... |
| CVE-2021-34377 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restricti... |
| CVE-2021-34376 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restricti... |
| CVE-2021-34375 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Trusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might... |
| CVE-2021-34374 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerabilit... |
| CVE-2021-34373 | MEDIUM | 6 | 0.3% | Jun 30, 2021 | Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could... |
| CVE-2021-31721 | MEDIUM | 6.1 | 1.2% | Jun 30, 2021 | Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage. |
| CVE-2021-28693 | MEDIUM | 5.5 | 0.3% | Jun 30, 2021 | xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary ... |
| CVE-2021-35959 | MEDIUM | 5.4 | 0.5% | Jun 30, 2021 | In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a fo... |
| CVE-2021-22341 | MEDIUM | 4.9 | 0.6% | Jun 29, 2021 | There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers wi... |
| CVE-2021-22329 | MEDIUM | 4.9 | 0.5% | Jun 29, 2021 | There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform s... |
| CVE-2021-32721 | MEDIUM | 6.1 | 0.6% | Jun 29, 2021 | PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to ... |
| CVE-2021-22340 | MEDIUM | 4.1 | 0.1% | Jun 29, 2021 | There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O r... |
| CVE-2021-22338 | MEDIUM | 5.3 | 0.6% | Jun 29, 2021 | There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict ope... |
| CVE-2021-20079 | MEDIUM | 6.7 | 0.4% | Jun 29, 2021 | Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus... |
| CVE-2021-20580 | MEDIUM | 4.3 | 0.4% | Jun 29, 2021 | IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to exe... |
| CVE-2021-20490 | MEDIUM | 5.5 | 0.2% | Jun 29, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure fi... |
| CVE-2021-20477 | MEDIUM | 5.4 | 0.5% | Jun 29, 2021 | IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now