2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38316MEDIUM6.1The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name param...
CVE-2021-28914MEDIUM6.5BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown ...
CVE-2021-25466MEDIUM5.9Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-th...
CVE-2021-25465HIGH7An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-...
CVE-2021-25464MEDIUM5.5An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.
CVE-2021-25463LOW3.3Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.
CVE-2021-25462MEDIUM5.5NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory co...
CVE-2021-25461HIGH7.8An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
CVE-2021-25460MEDIUM5.5An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta...
CVE-2021-25459MEDIUM5.5An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta...
CVE-2021-25458MEDIUM5.5NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory co...
CVE-2021-25457LOW3.3An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a...
CVE-2021-25456MEDIUM5.5OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy...
CVE-2021-25455LOW3.3OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitra...
CVE-2021-25454MEDIUM5.5OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote...
CVE-2021-25453MEDIUM5.5Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluet...
CVE-2021-25452MEDIUM5.5An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows at...
CVE-2021-25451LOW3.3A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI da...
CVE-2021-25450MEDIUM6.5Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file a...
CVE-2021-25449CRITICAL9.8An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers ...
CVE-2021-39296CRITICAL10In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
CVE-2021-28913CRITICAL9.8BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to v...
CVE-2021-28912HIGH7.2BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'ei...
CVE-2021-28911CRITICAL9.8BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains s...
CVE-2021-28910HIGH7.5BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attacker...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now