2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-1646MEDIUM6.6Windows WLAN Service Elevation of Privilege Vulnerability
CVE-2021-1645MEDIUM5Windows Docker Information Disclosure Vulnerability
CVE-2021-1641MEDIUM4.6Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-1637MEDIUM5.5Windows DNS Query Information Disclosure Vulnerability
CVE-2021-3133MEDIUM6.5The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.
CVE-2021-21471MEDIUM6.5In CLA-Assistant, versions before 2.8.5, due to improper access control an authenticated user could access API endpoints...
CVE-2021-21470MEDIUM4.4SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an...
CVE-2021-21468MEDIUM6.5The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escala...
CVE-2021-21467MEDIUM4.3SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, re...
CVE-2021-21464MEDIUM4.3SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources...
CVE-2021-21448MEDIUM6.5SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend s...
CVE-2021-21447MEDIUM5.4SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malici...
CVE-2021-21445MEDIUM5.4SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated dat...
CVE-2021-0322MEDIUM5In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input valid...
CVE-2021-0321MEDIUM5.5In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is ...
CVE-2021-0320MEDIUM4.7In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen ...
CVE-2021-0312MEDIUM6.5In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could l...
CVE-2021-0311MEDIUM6.5In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missi...
CVE-2021-0309MEDIUM5.5In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disc...
CVE-2021-0308MEDIUM6.8In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could le...
CVE-2021-0304MEDIUM5.5In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. Thi...
CVE-2021-0301MEDIUM6.7In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2021-0342MEDIUM6.7In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalati...
CVE-2021-23253MEDIUM5.3Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to cr...
CVE-2021-3111MEDIUM4.8The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now