2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35438 | MEDIUM | 6.1 | 1.0% | Jun 23, 2021 | phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of... |
| CVE-2021-28977 | MEDIUM | 4.8 | 0.5% | Jun 23, 2021 | Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file h... |
| CVE-2021-31585 | MEDIUM | 6.7 | 0.9% | Jun 23, 2021 | Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH pass... |
| CVE-2021-35210 | MEDIUM | 6.1 | 0.7% | Jun 23, 2021 | Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject ... |
| CVE-2021-34395 | MEDIUM | 4.2 | 0.2% | Jun 22, 2021 | Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a re... |
| CVE-2021-34394 | MEDIUM | 6.7 | 0.3% | Jun 22, 2021 | Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deser... |
| CVE-2021-34393 | MEDIUM | 4.4 | 0.3% | Jun 22, 2021 | Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not exp... |
| CVE-2021-34392 | MEDIUM | 5.5 | 0.2% | Jun 22, 2021 | Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function... |
| CVE-2021-34391 | MEDIUM | 5.5 | 0.2% | Jun 22, 2021 | Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an i... |
| CVE-2021-34390 | MEDIUM | 5.5 | 0.2% | Jun 22, 2021 | Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an i... |
| CVE-2021-32699 | MEDIUM | 6.5 | 0.3% | Jun 22, 2021 | Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl ... |
| CVE-2021-22383 | MEDIUM | 4.9 | 0.6% | Jun 22, 2021 | There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SP... |
| CVE-2021-22382 | MEDIUM | 6.5 | 0.2% | Jun 22, 2021 | Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and ... |
| CVE-2021-22378 | MEDIUM | 5.3 | 0.4% | Jun 22, 2021 | There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in wh... |
| CVE-2021-22342 | MEDIUM | 4.9 | 0.6% | Jun 22, 2021 | There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. ... |
| CVE-2021-32644 | MEDIUM | 5.4 | 0.8% | Jun 22, 2021 | Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering... |
| CVE-2021-22366 | MEDIUM | 5.5 | 0.2% | Jun 22, 2021 | There is an out-of-bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. Th... |
| CVE-2021-35206 | MEDIUM | 6.1 | 1.2% | Jun 22, 2021 | Gitpod before 0.6.0 allows unvalidated redirects. |
| CVE-2021-35046 | MEDIUM | 6.1 | 0.8% | Jun 22, 2021 | A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user ses... |
| CVE-2021-35045 | MEDIUM | 6.1 | 1.1% | Jun 22, 2021 | Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parame... |
| CVE-2021-34243 | MEDIUM | 5.4 | 0.6% | Jun 22, 2021 | A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute ... |
| CVE-2021-0606 | MEDIUM | 6.7 | 0.2% | Jun 22, 2021 | In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This coul... |
| CVE-2021-0605 | MEDIUM | 4.4 | 0.2% | Jun 22, 2021 | In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to loca... |
| CVE-2021-0552 | MEDIUM | 5.5 | 0.1% | Jun 22, 2021 | In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent.... |
| CVE-2021-0551 | MEDIUM | 6.5 | 0.6% | Jun 22, 2021 | In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now