2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1923 | HIGH | 7.8 | 0.1% | Sep 8, 2021 | Incorrect pointer argument passed to trusted application TA could result in un-intended memory operations in Snapdragon ... |
| CVE-2021-1920 | CRITICAL | 9.8 | 0.8% | Sep 8, 2021 | Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Sn... |
| CVE-2021-1919 | CRITICAL | 9.8 | 0.8% | Sep 8, 2021 | Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapd... |
| CVE-2021-1916 | CRITICAL | 9.8 | 0.8% | Sep 8, 2021 | Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdr... |
| CVE-2021-1914 | HIGH | 7.5 | 0.6% | Sep 8, 2021 | Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdra... |
| CVE-2021-1904 | MEDIUM | 5.5 | 0.5% | Sep 8, 2021 | Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reu... |
| CVE-2021-40377 | MEDIUM | 5.4 | 0.5% | Sep 8, 2021 | SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus al... |
| CVE-2021-36182 | HIGH | 8.8 | 1.9% | Sep 8, 2021 | A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.1... |
| CVE-2021-36179 | HIGH | 8.8 | 1.5% | Sep 8, 2021 | A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute ... |
| CVE-2021-23404 | HIGH | 8.8 | 0.5% | Sep 8, 2021 | This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without... |
| CVE-2021-39122 | MEDIUM | 5.3 | 1.4% | Sep 8, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an... |
| CVE-2021-39121 | MEDIUM | 4.3 | 1.1% | Sep 8, 2021 | Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of... |
| CVE-2021-39116 | MEDIUM | 5.5 | 1.0% | Sep 8, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili... |
| CVE-2021-37145 | HIGH | 7.2 | 2.0% | Sep 7, 2021 | A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3... |
| CVE-2021-32802 | CRITICAL | 9.8 | 2.5% | Sep 7, 2021 | Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user pro... |
| CVE-2021-32801 | MEDIUM | 5.5 | 0.2% | Sep 7, 2021 | Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resu... |
| CVE-2021-32800 | HIGH | 8.1 | 1.7% | Sep 7, 2021 | Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two F... |
| CVE-2021-39501 | MEDIUM | 6.1 | 3.4% | Sep 7, 2021 | EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function... |
| CVE-2021-39500 | HIGH | 7.5 | 1.4% | Sep 7, 2021 | Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, t... |
| CVE-2021-37629 | MEDIUM | 5.3 | 1.3% | Sep 7, 2021 | Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limit... |
| CVE-2021-37628 | HIGH | 7.5 | 2.0% | Sep 7, 2021 | Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Uplo... |
| CVE-2021-32766 | MEDIUM | 5.3 | 1.3% | Sep 7, 2021 | Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versio... |
| CVE-2021-40143 | HIGH | 8.2 | 2.2% | Sep 7, 2021 | Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP req... |
| CVE-2021-39503 | HIGH | 7.2 | 2.7% | Sep 7, 2021 | PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConf... |
| CVE-2021-39499 | MEDIUM | 6.1 | 1.2% | Sep 7, 2021 | A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitra... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now