2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22906MEDIUM6.5Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to perm...
CVE-2021-22905MEDIUM6.5Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for ...
CVE-2021-22903MEDIUM6.1The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host heade...
CVE-2021-22897MEDIUM5.3curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLO...
CVE-2021-22896MEDIUM4.3Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authen...
CVE-2021-22895MEDIUM5.9Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate ve...
CVE-2021-22769MEDIUM4.3A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1...
CVE-2021-22764MEDIUM5.3A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and P...
CVE-2021-22749MEDIUM5.3A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RT...
CVE-2021-22181MEDIUM6.5A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recur...
CVE-2021-28689MEDIUM5.5x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the...
CVE-2021-28687MEDIUM5.5HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized...
CVE-2021-25425MEDIUM5.3Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exp...
CVE-2021-25423MEDIUM5.5Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log ...
CVE-2021-25422MEDIUM5.5Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log p...
CVE-2021-25421MEDIUM5.5Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log ...
CVE-2021-25420MEDIUM5.5Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log p...
CVE-2021-25419MEDIUM6.5Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to di...
CVE-2021-25416MEDIUM6.5Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attacker...
CVE-2021-25415MEDIUM5.5Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attacker...
CVE-2021-25413MEDIUM5.5Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to g...
CVE-2021-25411MEDIUM4.4Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attack...
CVE-2021-25406MEDIUM6.5Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to a...
CVE-2021-25405MEDIUM5.5An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrust...
CVE-2021-25397MEDIUM5.5An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now