2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-35438MEDIUM6.1phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of...
CVE-2021-28977MEDIUM4.8Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file h...
CVE-2021-31585MEDIUM6.7Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH pass...
CVE-2021-35210MEDIUM6.1Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject ...
CVE-2021-34395MEDIUM4.2Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a re...
CVE-2021-34394MEDIUM6.7Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deser...
CVE-2021-34393MEDIUM4.4Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not exp...
CVE-2021-34392MEDIUM5.5Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function...
CVE-2021-34391MEDIUM5.5Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an i...
CVE-2021-34390MEDIUM5.5Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an i...
CVE-2021-32699MEDIUM6.5Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl ...
CVE-2021-22383MEDIUM4.9There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SP...
CVE-2021-22382MEDIUM6.5Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and ...
CVE-2021-22378MEDIUM5.3There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in wh...
CVE-2021-22342MEDIUM4.9There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. ...
CVE-2021-32644MEDIUM5.4Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering...
CVE-2021-22366MEDIUM5.5There is an out-of-bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. Th...
CVE-2021-35206MEDIUM6.1Gitpod before 0.6.0 allows unvalidated redirects.
CVE-2021-35046MEDIUM6.1A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user ses...
CVE-2021-35045MEDIUM6.1Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parame...
CVE-2021-34243MEDIUM5.4A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute ...
CVE-2021-0606MEDIUM6.7In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This coul...
CVE-2021-0605MEDIUM4.4In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to loca...
CVE-2021-0552MEDIUM5.5In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent....
CVE-2021-0551MEDIUM6.5In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now