2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21483MEDIUM4.9Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensiti...
CVE-2021-0471MEDIUM5.5In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead t...
CVE-2021-0468MEDIUM6.6In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation...
CVE-2021-0444MEDIUM5.5In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This could lead to local ...
CVE-2021-0443MEDIUM4.7In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to...
CVE-2021-0436MEDIUM5.5In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could...
CVE-2021-0428MEDIUM5.5In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing ...
CVE-2021-0400MEDIUM5.5In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of ...
CVE-2021-29997MEDIUM5.3An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on...
CVE-2021-28973MEDIUM4.9The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input dat...
CVE-2021-21729MEDIUM6.5Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perfo...
CVE-2021-28646MEDIUM5.5An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could al...
CVE-2021-29425MEDIUM4.8In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "/...
CVE-2021-28938MEDIUM4.3Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10....
CVE-2021-30637MEDIUM5.4htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
CVE-2021-30044MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
CVE-2021-30042MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont...
CVE-2021-30039MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo...
CVE-2021-30034MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
CVE-2021-30030MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
CVE-2021-29429MEDIUM5.5In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacke...
CVE-2021-21393MEDIUM6.5Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-21392MEDIUM6.3Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-3163MEDIUM6.1A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an ...
CVE-2021-21394MEDIUM6.5Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now