2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29482 | HIGH | 7.5 | 1.4% | Apr 28, 2021 | xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvari... |
| CVE-2021-25154 | HIGH | 7.5 | 1.0% | Apr 28, 2021 | A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8... |
| CVE-2021-25153 | HIGH | 8.1 | 1.1% | Apr 28, 2021 | A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. A... |
| CVE-2021-25151 | HIGH | 8.8 | 12.6% | Apr 28, 2021 | A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to ... |
| CVE-2021-25147 | HIGH | 8.1 | 1.3% | Apr 28, 2021 | A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) ... |
| CVE-2021-22332 | HIGH | 7.5 | 0.7% | Apr 28, 2021 | There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 an... |
| CVE-2021-22331 | HIGH | 7.5 | 0.7% | Apr 28, 2021 | There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs suffic... |
| CVE-2021-22393 | HIGH | 7.5 | 0.7% | Apr 28, 2021 | There is a denial of service vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and ... |
| CVE-2021-30169 | HIGH | 7.5 | 1.7% | Apr 28, 2021 | The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s ... |
| CVE-2021-30166 | HIGH | 7.2 | 3.8% | Apr 28, 2021 | The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers ... |
| CVE-2021-27648 | HIGH | 8.8 | 2.8% | Apr 28, 2021 | Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essent... |
| CVE-2021-31863 | HIGH | 7.5 | 1.7% | Apr 28, 2021 | Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x b... |
| CVE-2021-3512 | HIGH | 8.8 | 0.9% | Apr 28, 2021 | Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH ... |
| CVE-2021-29472 | HIGH | 8.8 | 4.8% | Apr 27, 2021 | Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source d... |
| CVE-2021-29442 | HIGH | 7.5 | 64.7% | Apr 27, 2021 | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver... |
| CVE-2021-30638 | HIGH | 7.5 | 6.6% | Apr 27, 2021 | Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files ins... |
| CVE-2021-29667 | HIGH | 7.8 | 1.2% | Apr 27, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote ... |
| CVE-2021-3464 | HIGH | 7.8 | 0.3% | Apr 27, 2021 | A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privil... |
| CVE-2021-28269 | HIGH | 8.8 | 1.9% | Apr 27, 2021 | Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users gr... |
| CVE-2021-28271 | HIGH | 8.8 | 1.9% | Apr 27, 2021 | Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an a... |
| CVE-2021-22664 | HIGH | 7.8 | 1.6% | Apr 27, 2021 | CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds write, which may allow an attacker to execute arb... |
| CVE-2021-22660 | HIGH | 7.8 | 2.0% | Apr 27, 2021 | CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbi... |
| CVE-2021-31826 | HIGH | 7.5 | 2.0% | Apr 27, 2021 | Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery ... |
| CVE-2021-31671 | HIGH | 7.5 | 0.7% | Apr 27, 2021 | pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema... |
| CVE-2021-30165 | HIGH | 8.1 | 1.1% | Apr 27, 2021 | The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can d... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now