2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38316 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name param... |
| CVE-2021-28914 | MEDIUM | 6.5 | 1.0% | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown ... |
| CVE-2021-25466 | MEDIUM | 5.9 | 0.7% | Sep 9, 2021 | Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-th... |
| CVE-2021-25465 | HIGH | 7 | 0.2% | Sep 9, 2021 | An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-... |
| CVE-2021-25464 | MEDIUM | 5.5 | 0.3% | Sep 9, 2021 | An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak. |
| CVE-2021-25463 | LOW | 3.3 | 0.2% | Sep 9, 2021 | Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview. |
| CVE-2021-25462 | MEDIUM | 5.5 | 0.1% | Sep 9, 2021 | NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory co... |
| CVE-2021-25461 | HIGH | 7.8 | 0.2% | Sep 9, 2021 | An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow. |
| CVE-2021-25460 | MEDIUM | 5.5 | 0.1% | Sep 9, 2021 | An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta... |
| CVE-2021-25459 | MEDIUM | 5.5 | 0.1% | Sep 9, 2021 | An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta... |
| CVE-2021-25458 | MEDIUM | 5.5 | 0.1% | Sep 9, 2021 | NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory co... |
| CVE-2021-25457 | LOW | 3.3 | 0.1% | Sep 9, 2021 | An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a... |
| CVE-2021-25456 | MEDIUM | 5.5 | 0.2% | Sep 9, 2021 | OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy... |
| CVE-2021-25455 | LOW | 3.3 | 0.2% | Sep 9, 2021 | OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitra... |
| CVE-2021-25454 | MEDIUM | 5.5 | 0.2% | Sep 9, 2021 | OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote... |
| CVE-2021-25453 | MEDIUM | 5.5 | 0.1% | Sep 9, 2021 | Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluet... |
| CVE-2021-25452 | MEDIUM | 5.5 | 0.1% | Sep 9, 2021 | An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows at... |
| CVE-2021-25451 | LOW | 3.3 | 0.2% | Sep 9, 2021 | A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI da... |
| CVE-2021-25450 | MEDIUM | 6.5 | 0.2% | Sep 9, 2021 | Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file a... |
| CVE-2021-25449 | CRITICAL | 9.8 | 0.4% | Sep 9, 2021 | An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers ... |
| CVE-2021-39296 | CRITICAL | 10 | 2.9% | Sep 9, 2021 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. |
| CVE-2021-28913 | CRITICAL | 9.8 | 1.8% | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to v... |
| CVE-2021-28912 | HIGH | 7.2 | 1.2% | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'ei... |
| CVE-2021-28911 | CRITICAL | 9.8 | 1.6% | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains s... |
| CVE-2021-28910 | HIGH | 7.5 | 1.1% | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attacker... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now