2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25228 | MEDIUM | 5.3 | 2.1% | Feb 4, 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free B... |
| CVE-2021-0350 | MEDIUM | 4.4 | 0.1% | Feb 4, 2021 | In ged, there is a possible system crash due to an improper input validation. This could lead to local denial of service... |
| CVE-2021-0349 | MEDIUM | 6.7 | 0.2% | Feb 4, 2021 | In display driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of... |
| CVE-2021-0348 | MEDIUM | 6.7 | 0.2% | Feb 4, 2021 | In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2021-0347 | MEDIUM | 4.4 | 0.2% | Feb 4, 2021 | In ccu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl... |
| CVE-2021-0346 | MEDIUM | 6.7 | 0.2% | Feb 4, 2021 | In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of... |
| CVE-2021-0345 | MEDIUM | 6.7 | 0.2% | Feb 4, 2021 | In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local ... |
| CVE-2021-0344 | MEDIUM | 6.7 | 0.2% | Feb 4, 2021 | In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of... |
| CVE-2021-0343 | MEDIUM | 6.7 | 0.2% | Feb 4, 2021 | In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
| CVE-2021-1389 | MEDIUM | 6.5 | 1.2% | Feb 4, 2021 | A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devic... |
| CVE-2021-1268 | MEDIUM | 6.5 | 0.5% | Feb 4, 2021 | A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unaut... |
| CVE-2021-1266 | MEDIUM | 6.5 | 1.1% | Feb 4, 2021 | A vulnerability in the REST API of Cisco Managed Services Accelerator (MSX) could allow an authenticated, remote attacke... |
| CVE-2021-1244 | MEDIUM | 6.7 | 0.2% | Feb 4, 2021 | Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NC... |
| CVE-2021-1221 | MEDIUM | 4.1 | 1.0% | Feb 4, 2021 | A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an au... |
| CVE-2021-1136 | MEDIUM | 6.7 | 0.2% | Feb 4, 2021 | Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NC... |
| CVE-2021-1128 | MEDIUM | 5.5 | 0.3% | Feb 4, 2021 | A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local attacker to view more inf... |
| CVE-2021-26024 | MEDIUM | 5.3 | 19.0% | Feb 3, 2021 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possib... |
| CVE-2021-26023 | MEDIUM | 6.1 | 25.2% | Feb 3, 2021 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS. |
| CVE-2021-25778 | MEDIUM | 5.3 | 0.8% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly. |
| CVE-2021-25777 | MEDIUM | 5.3 | 0.7% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. |
| CVE-2021-25774 | MEDIUM | 4.3 | 0.7% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user. |
| CVE-2021-25773 | MEDIUM | 6.1 | 0.6% | Feb 3, 2021 | JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages. |
| CVE-2021-25772 | MEDIUM | 5.3 | 1.0% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration. |
| CVE-2021-25771 | MEDIUM | 4.3 | 1.5% | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed. |
| CVE-2021-25768 | MEDIUM | 5.3 | 1.2% | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now