2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21483 | MEDIUM | 4.9 | 0.7% | Apr 13, 2021 | Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensiti... |
| CVE-2021-0471 | MEDIUM | 5.5 | 0.1% | Apr 13, 2021 | In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead t... |
| CVE-2021-0468 | MEDIUM | 6.6 | 0.1% | Apr 13, 2021 | In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation... |
| CVE-2021-0444 | MEDIUM | 5.5 | 0.1% | Apr 13, 2021 | In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This could lead to local ... |
| CVE-2021-0443 | MEDIUM | 4.7 | 0.1% | Apr 13, 2021 | In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to... |
| CVE-2021-0436 | MEDIUM | 5.5 | 0.1% | Apr 13, 2021 | In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could... |
| CVE-2021-0428 | MEDIUM | 5.5 | 0.1% | Apr 13, 2021 | In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing ... |
| CVE-2021-0400 | MEDIUM | 5.5 | 0.1% | Apr 13, 2021 | In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of ... |
| CVE-2021-29997 | MEDIUM | 5.3 | 1.0% | Apr 13, 2021 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on... |
| CVE-2021-28973 | MEDIUM | 4.9 | 0.9% | Apr 13, 2021 | The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input dat... |
| CVE-2021-21729 | MEDIUM | 6.5 | 0.4% | Apr 13, 2021 | Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perfo... |
| CVE-2021-28646 | MEDIUM | 5.5 | 0.4% | Apr 13, 2021 | An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could al... |
| CVE-2021-29425 | MEDIUM | 4.8 | 10.6% | Apr 13, 2021 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "/... |
| CVE-2021-28938 | MEDIUM | 4.3 | 0.8% | Apr 13, 2021 | Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10.... |
| CVE-2021-30637 | MEDIUM | 5.4 | 1.9% | Apr 13, 2021 | htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php. |
| CVE-2021-30044 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php. |
| CVE-2021-30042 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont... |
| CVE-2021-30039 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo... |
| CVE-2021-30034 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php. |
| CVE-2021-30030 | MEDIUM | 5.4 | 1.8% | Apr 13, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php. |
| CVE-2021-29429 | MEDIUM | 5.5 | 0.5% | Apr 12, 2021 | In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacke... |
| CVE-2021-21393 | MEDIUM | 6.5 | 1.6% | Apr 12, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-21392 | MEDIUM | 6.3 | 0.9% | Apr 12, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-3163 | MEDIUM | 6.1 | 1.3% | Apr 12, 2021 | A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an ... |
| CVE-2021-21394 | MEDIUM | 6.5 | 1.5% | Apr 12, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now