2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22906 | MEDIUM | 6.5 | 0.7% | Jun 11, 2021 | Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to perm... |
| CVE-2021-22905 | MEDIUM | 6.5 | 1.4% | Jun 11, 2021 | Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for ... |
| CVE-2021-22903 | MEDIUM | 6.1 | 1.2% | Jun 11, 2021 | The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host heade... |
| CVE-2021-22897 | MEDIUM | 5.3 | 3.0% | Jun 11, 2021 | curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLO... |
| CVE-2021-22896 | MEDIUM | 4.3 | 1.0% | Jun 11, 2021 | Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authen... |
| CVE-2021-22895 | MEDIUM | 5.9 | 1.0% | Jun 11, 2021 | Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate ve... |
| CVE-2021-22769 | MEDIUM | 4.3 | 0.6% | Jun 11, 2021 | A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1... |
| CVE-2021-22764 | MEDIUM | 5.3 | 1.9% | Jun 11, 2021 | A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and P... |
| CVE-2021-22749 | MEDIUM | 5.3 | 0.9% | Jun 11, 2021 | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RT... |
| CVE-2021-22181 | MEDIUM | 6.5 | 1.1% | Jun 11, 2021 | A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recur... |
| CVE-2021-28689 | MEDIUM | 5.5 | 0.4% | Jun 11, 2021 | x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the... |
| CVE-2021-28687 | MEDIUM | 5.5 | 0.3% | Jun 11, 2021 | HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized... |
| CVE-2021-25425 | MEDIUM | 5.3 | 0.8% | Jun 11, 2021 | Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exp... |
| CVE-2021-25423 | MEDIUM | 5.5 | 0.2% | Jun 11, 2021 | Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log ... |
| CVE-2021-25422 | MEDIUM | 5.5 | 0.2% | Jun 11, 2021 | Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log p... |
| CVE-2021-25421 | MEDIUM | 5.5 | 0.2% | Jun 11, 2021 | Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log ... |
| CVE-2021-25420 | MEDIUM | 5.5 | 0.2% | Jun 11, 2021 | Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log p... |
| CVE-2021-25419 | MEDIUM | 6.5 | 0.8% | Jun 11, 2021 | Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to di... |
| CVE-2021-25416 | MEDIUM | 6.5 | 0.1% | Jun 11, 2021 | Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attacker... |
| CVE-2021-25415 | MEDIUM | 5.5 | 0.1% | Jun 11, 2021 | Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attacker... |
| CVE-2021-25413 | MEDIUM | 5.5 | 0.2% | Jun 11, 2021 | Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to g... |
| CVE-2021-25411 | MEDIUM | 4.4 | 0.1% | Jun 11, 2021 | Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attack... |
| CVE-2021-25406 | MEDIUM | 6.5 | 0.4% | Jun 11, 2021 | Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to a... |
| CVE-2021-25405 | MEDIUM | 5.5 | 0.2% | Jun 11, 2021 | An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrust... |
| CVE-2021-25397 | MEDIUM | 5.5 | 0.1% | Jun 11, 2021 | An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now