2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-25396MEDIUM6.7An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write...
CVE-2021-25395MEDIUM6.4A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check ...
CVE-2021-25394MEDIUM6.4A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary...
CVE-2021-25393MEDIUM5.5Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get pe...
CVE-2021-25392MEDIUM5.5Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers t...
CVE-2021-25391MEDIUM4Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged...
CVE-2021-25390MEDIUM4Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged ac...
CVE-2021-25389MEDIUM6.1Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authe...
CVE-2021-26993MEDIUM5.3E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when ...
CVE-2021-26997MEDIUM6.5E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when ...
CVE-2021-34540MEDIUM6.1Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.
CVE-2021-26829MEDIUM5.4OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
CVE-2021-28805MEDIUM5.5Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If ...
CVE-2021-23393MEDIUM5.4This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possibl...
CVE-2021-26199MEDIUM6.5An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file...
CVE-2021-26198MEDIUM6.5An issue was discovered in JerryScript 2.4.0. There is a SEVG in ecma_deref_bigint in ecma-helpers.c file.
CVE-2021-26197MEDIUM6.5An issue was discovered in JerryScript 2.4.0. There is a SEGV in main_print_unhandled_exception in main-utils.c file.
CVE-2021-26194MEDIUM6.5An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_is_lexical_environment in the ecma-...
CVE-2021-20329MEDIUM6.5Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A ...
CVE-2021-34557MEDIUM4.6XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in up...
CVE-2021-34546MEDIUM6.8An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre...
CVE-2021-27347MEDIUM5.5Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (D...
CVE-2021-27345MEDIUM5.5A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a de...
CVE-2021-34547MEDIUM4.3PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.
CVE-2021-31927MEDIUM4.3An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now