2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30819 | MEDIUM | 5.5 | 0.8% | Oct 19, 2021 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 and iPadOS 15. Process... |
| CVE-2021-30815 | LOW | 2.4 | 0.3% | Oct 19, 2021 | A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state manageme... |
| CVE-2021-30811 | MEDIUM | 5.5 | 0.3% | Oct 19, 2021 | This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker ... |
| CVE-2021-30810 | MEDIUM | 4.3 | 0.5% | Oct 19, 2021 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchO... |
| CVE-2021-30807 | HIGH | 7.8 | 28.8% | Oct 19, 2021 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS ... |
| CVE-2021-30358 | HIGH | 7.2 | 27.5% | Oct 19, 2021 | Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run a... |
| CVE-2021-3889 | HIGH | 8.1 | 1.2% | Oct 19, 2021 | libmobi is vulnerable to Use of Out-of-range Pointer Offset |
| CVE-2021-3888 | HIGH | 8.1 | 1.2% | Oct 19, 2021 | libmobi is vulnerable to Use of Out-of-range Pointer Offset |
| CVE-2021-3879 | MEDIUM | 5.4 | 0.8% | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3872 | HIGH | 7.8 | 1.4% | Oct 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-3869 | HIGH | 7.5 | 1.3% | Oct 19, 2021 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference |
| CVE-2021-3863 | MEDIUM | 6.1 | 0.8% | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3858 | HIGH | 8.8 | 0.5% | Oct 19, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3851 | MEDIUM | 5.4 | 0.6% | Oct 19, 2021 | firefly-iii is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-3846 | HIGH | 8.8 | 0.8% | Oct 19, 2021 | firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type |
| CVE-2021-38486 | HIGH | 8.5 | 0.8% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the aff... |
| CVE-2021-38484 | HIGH | 7.2 | 2.6% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or... |
| CVE-2021-38482 | MEDIUM | 4.8 | 0.5% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 website used to control the router is vulnerable to ... |
| CVE-2021-38480 | HIGH | 8.8 | 0.5% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when un... |
| CVE-2021-38478 | CRITICAL | 9.1 | 1.1% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute too... |
| CVE-2021-38476 | MEDIUM | 5.3 | 0.7% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and valida... |
| CVE-2021-38474 | CRITICAL | 9.8 | 0.7% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for th... |
| CVE-2021-38472 | MEDIUM | 4.7 | 0.7% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTION... |
| CVE-2021-38470 | CRITICAL | 9.1 | 1.1% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to i... |
| CVE-2021-38468 | MEDIUM | 4.8 | 0.5% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to stored cross-scripting, which may ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now