2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-1923HIGH7.8Incorrect pointer argument passed to trusted application TA could result in un-intended memory operations in Snapdragon ...
CVE-2021-1920CRITICAL9.8Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Sn...
CVE-2021-1919CRITICAL9.8Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapd...
CVE-2021-1916CRITICAL9.8Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdr...
CVE-2021-1914HIGH7.5Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdra...
CVE-2021-1904MEDIUM5.5Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reu...
CVE-2021-40377MEDIUM5.4SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus al...
CVE-2021-36182HIGH8.8A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.1...
CVE-2021-36179HIGH8.8A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute ...
CVE-2021-23404HIGH8.8This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without...
CVE-2021-39122MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an...
CVE-2021-39121MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of...
CVE-2021-39116MEDIUM5.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili...
CVE-2021-37145HIGH7.2A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3...
CVE-2021-32802CRITICAL9.8Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user pro...
CVE-2021-32801MEDIUM5.5Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resu...
CVE-2021-32800HIGH8.1Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two F...
CVE-2021-39501MEDIUM6.1EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function...
CVE-2021-39500HIGH7.5Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, t...
CVE-2021-37629MEDIUM5.3Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limit...
CVE-2021-37628HIGH7.5Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Uplo...
CVE-2021-32766MEDIUM5.3Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versio...
CVE-2021-40143HIGH8.2Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP req...
CVE-2021-39503HIGH7.2PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConf...
CVE-2021-39499MEDIUM6.1A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitra...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now