2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1646 | MEDIUM | 6.6 | 0.8% | Jan 12, 2021 | Windows WLAN Service Elevation of Privilege Vulnerability |
| CVE-2021-1645 | MEDIUM | 5 | 7.3% | Jan 12, 2021 | Windows Docker Information Disclosure Vulnerability |
| CVE-2021-1641 | MEDIUM | 4.6 | 1.8% | Jan 12, 2021 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2021-1637 | MEDIUM | 5.5 | 1.2% | Jan 12, 2021 | Windows DNS Query Information Disclosure Vulnerability |
| CVE-2021-3133 | MEDIUM | 6.5 | 0.9% | Jan 12, 2021 | The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages. |
| CVE-2021-21471 | MEDIUM | 6.5 | 0.7% | Jan 12, 2021 | In CLA-Assistant, versions before 2.8.5, due to improper access control an authenticated user could access API endpoints... |
| CVE-2021-21470 | MEDIUM | 4.4 | 0.2% | Jan 12, 2021 | SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an... |
| CVE-2021-21468 | MEDIUM | 6.5 | 1.9% | Jan 12, 2021 | The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escala... |
| CVE-2021-21467 | MEDIUM | 4.3 | 0.8% | Jan 12, 2021 | SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, re... |
| CVE-2021-21464 | MEDIUM | 4.3 | 1.0% | Jan 12, 2021 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources... |
| CVE-2021-21448 | MEDIUM | 6.5 | 0.3% | Jan 12, 2021 | SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend s... |
| CVE-2021-21447 | MEDIUM | 5.4 | 0.5% | Jan 12, 2021 | SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malici... |
| CVE-2021-21445 | MEDIUM | 5.4 | 0.6% | Jan 12, 2021 | SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated dat... |
| CVE-2021-0322 | MEDIUM | 5 | 0.2% | Jan 11, 2021 | In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input valid... |
| CVE-2021-0321 | MEDIUM | 5.5 | 0.2% | Jan 11, 2021 | In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is ... |
| CVE-2021-0320 | MEDIUM | 4.7 | 0.1% | Jan 11, 2021 | In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen ... |
| CVE-2021-0312 | MEDIUM | 6.5 | 1.1% | Jan 11, 2021 | In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could l... |
| CVE-2021-0311 | MEDIUM | 6.5 | 1.1% | Jan 11, 2021 | In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missi... |
| CVE-2021-0309 | MEDIUM | 5.5 | 0.2% | Jan 11, 2021 | In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disc... |
| CVE-2021-0308 | MEDIUM | 6.8 | 0.4% | Jan 11, 2021 | In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could le... |
| CVE-2021-0304 | MEDIUM | 5.5 | 0.2% | Jan 11, 2021 | In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. Thi... |
| CVE-2021-0301 | MEDIUM | 6.7 | 0.2% | Jan 11, 2021 | In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2021-0342 | MEDIUM | 6.7 | 0.2% | Jan 11, 2021 | In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalati... |
| CVE-2021-23253 | MEDIUM | 5.3 | 0.8% | Jan 11, 2021 | Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to cr... |
| CVE-2021-3111 | MEDIUM | 4.8 | 3.0% | Jan 8, 2021 | The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now