2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21349 | HIGH | 8.6 | 47.8% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21348 | HIGH | 7.5 | 14.2% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21343 | HIGH | 7.5 | 47.6% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21341 | HIGH | 7.5 | 77.9% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnera... |
| CVE-2021-22314 | HIGH | 7.8 | 0.2% | Mar 22, 2021 | There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could ... |
| CVE-2021-22320 | HIGH | 7.5 | 0.7% | Mar 22, 2021 | There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. At... |
| CVE-2021-22311 | HIGH | 7.2 | 0.7% | Mar 22, 2021 | There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening... |
| CVE-2021-26578 | HIGH | 7.5 | 1.0% | Mar 22, 2021 | A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The ... |
| CVE-2021-25265 | HIGH | 8.8 | 1.8% | Mar 22, 2021 | A malicious website could execute code remotely in Sophos Connect Client before version 2.1. |
| CVE-2021-22309 | HIGH | 7.5 | 0.8% | Mar 22, 2021 | There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Att... |
| CVE-2021-28148 | HIGH | 7.5 | 3.5% | Mar 22, 2021 | One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before... |
| CVE-2021-27962 | HIGH | 7.1 | 2.1% | Mar 22, 2021 | Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission... |
| CVE-2021-28956 | HIGH | 8.8 | 1.5% | Mar 22, 2021 | The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execu... |
| CVE-2021-26070 | HIGH | 7.2 | 2.0% | Mar 22, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protectio... |
| CVE-2021-23360 | HIGH | 8.8 | 2.3% | Mar 21, 2021 | This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an atta... |
| CVE-2021-28961 | HIGH | 8.8 | 1.5% | Mar 21, 2021 | applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenti... |
| CVE-2021-28954 | HIGH | 7.8 | 1.0% | Mar 21, 2021 | In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository. |
| CVE-2021-28953 | HIGH | 7.8 | 1.0% | Mar 21, 2021 | The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary b... |
| CVE-2021-28952 | HIGH | 7.8 | 0.4% | Mar 20, 2021 | An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a bu... |
| CVE-2021-28117 | HIGH | 7.5 | 1.6% | Mar 20, 2021 | libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially... |
| CVE-2021-21267 | HIGH | 7.5 | 2.1% | Mar 19, 2021 | Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before ve... |
| CVE-2021-26992 | HIGH | 7.5 | 1.4% | Mar 19, 2021 | Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a ... |
| CVE-2021-26991 | HIGH | 7.5 | 1.2% | Mar 19, 2021 | Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow ... |
| CVE-2021-21387 | HIGH | 7.5 | 0.4% | Mar 19, 2021 | Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.... |
| CVE-2021-28831 | HIGH | 7.5 | 2.8% | Mar 19, 2021 | decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultan... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now