2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25396 | MEDIUM | 6.7 | 0.1% | Jun 11, 2021 | An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write... |
| CVE-2021-25395 | MEDIUM | 6.4 | 0.4% | Jun 11, 2021 | A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check ... |
| CVE-2021-25394 | MEDIUM | 6.4 | 0.4% | Jun 11, 2021 | A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary... |
| CVE-2021-25393 | MEDIUM | 5.5 | 0.1% | Jun 11, 2021 | Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get pe... |
| CVE-2021-25392 | MEDIUM | 5.5 | 0.1% | Jun 11, 2021 | Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers t... |
| CVE-2021-25391 | MEDIUM | 4 | 0.2% | Jun 11, 2021 | Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged... |
| CVE-2021-25390 | MEDIUM | 4 | 0.2% | Jun 11, 2021 | Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged ac... |
| CVE-2021-25389 | MEDIUM | 6.1 | 0.1% | Jun 11, 2021 | Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authe... |
| CVE-2021-26993 | MEDIUM | 5.3 | 1.4% | Jun 11, 2021 | E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when ... |
| CVE-2021-26997 | MEDIUM | 6.5 | 1.1% | Jun 11, 2021 | E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when ... |
| CVE-2021-34540 | MEDIUM | 6.1 | 0.9% | Jun 11, 2021 | Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard. |
| CVE-2021-26829 | MEDIUM | 5.4 | 48.0% | Jun 11, 2021 | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. |
| CVE-2021-28805 | MEDIUM | 5.5 | 0.2% | Jun 11, 2021 | Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If ... |
| CVE-2021-23393 | MEDIUM | 5.4 | 0.7% | Jun 11, 2021 | This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possibl... |
| CVE-2021-26199 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file... |
| CVE-2021-26198 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a SEVG in ecma_deref_bigint in ecma-helpers.c file. |
| CVE-2021-26197 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a SEGV in main_print_unhandled_exception in main-utils.c file. |
| CVE-2021-26194 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_is_lexical_environment in the ecma-... |
| CVE-2021-20329 | MEDIUM | 6.5 | 1.0% | Jun 10, 2021 | Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A ... |
| CVE-2021-34557 | MEDIUM | 4.6 | 0.5% | Jun 10, 2021 | XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in up... |
| CVE-2021-34546 | MEDIUM | 6.8 | 0.7% | Jun 10, 2021 | An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre... |
| CVE-2021-27347 | MEDIUM | 5.5 | 0.7% | Jun 10, 2021 | Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (D... |
| CVE-2021-27345 | MEDIUM | 5.5 | 0.7% | Jun 10, 2021 | A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a de... |
| CVE-2021-34547 | MEDIUM | 4.3 | 0.4% | Jun 10, 2021 | PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation. |
| CVE-2021-31927 | MEDIUM | 4.3 | 0.5% | Jun 10, 2021 | An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now