2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37003HIGH7.5There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability wi...
CVE-2021-35052HIGH7.8A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to Hi...
CVE-2021-22356MEDIUM5.9There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attacker...
CVE-2021-39976HIGH7.8There is a privilege escalation vulnerability in CloudEngine 5800 V200R020C00SPC600. Due to lack of privilege restrictio...
CVE-2021-37036MEDIUM5.5There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the...
CVE-2021-22410MEDIUM5.4There is a XSS injection vulnerability in iMaster NCE-Fabric V100R019C10. A module of the client does not verify the inp...
CVE-2021-20601HIGH7.5Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all version...
CVE-2021-40831HIGH7.2The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the ro...
CVE-2021-40830HIGH8.8The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the ro...
CVE-2021-40829HIGH8.8Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1...
CVE-2021-40828HIGH8.8Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.1...
CVE-2021-44150HIGH7.5The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.
CVE-2021-44147MEDIUM5.5An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote atta...
CVE-2021-44144CRITICAL9.1Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date...
CVE-2021-32004MEDIUM5.3This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secome...
CVE-2021-44143CRITICAL9.8A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP ...
CVE-2021-42707HIGH7.8PLC Editor Versions 1.3.8 and prior is vulnerable to an out-of-bounds write while processing project files, which may al...
CVE-2021-42705HIGH7.8PLC Editor Versions 1.3.8 and prior is vulnerable to a stack-based buffer overflow while processing project files, which...
CVE-2021-38448HIGH7.6The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft...
CVE-2021-23732CRITICAL9This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least b...
CVE-2021-23718HIGH7.5The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker functi...
CVE-2021-23673MEDIUM6.1This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains java...
CVE-2021-43560MEDIUM5.3A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. I...
CVE-2021-43559HIGH8.8A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. T...
CVE-2021-43558MEDIUM6.1A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now