2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30346 | MEDIUM | 5.5 | 0.2% | Jun 14, 2022 | RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdr... |
| CVE-2021-30345 | MEDIUM | 5.5 | 0.2% | Jun 14, 2022 | RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdr... |
| CVE-2021-30343 | MEDIUM | 5.9 | 0.4% | Jun 14, 2022 | Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has bee... |
| CVE-2021-30342 | MEDIUM | 5.9 | 0.4% | Jun 14, 2022 | Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has bee... |
| CVE-2021-30339 | MEDIUM | 5.5 | 0.2% | Jun 14, 2022 | Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Sna... |
| CVE-2021-30338 | MEDIUM | 5.5 | 0.2% | Jun 14, 2022 | Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Comput... |
| CVE-2021-30327 | MEDIUM | 6.8 | 0.2% | Jun 14, 2022 | Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdrag... |
| CVE-2021-41663 | MEDIUM | 6.1 | 1.0% | Jun 13, 2022 | A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: pos... |
| CVE-2021-46811 | MEDIUM | 5.3 | 0.5% | Jun 13, 2022 | HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause dis... |
| CVE-2021-40902 | MEDIUM | 5.4 | 0.4% | Jun 13, 2022 | flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index p... |
| CVE-2021-25116 | MEDIUM | 6.5 | 0.4% | Jun 13, 2022 | The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX... |
| CVE-2021-41750 | MEDIUM | 6.1 | 1.0% | Jun 12, 2022 | A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inje... |
| CVE-2021-44266 | MEDIUM | 6.1 | 1.0% | Jun 11, 2022 | GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter. |
| CVE-2021-41502 | MEDIUM | 5.4 | 0.5% | Jun 11, 2022 | An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execut... |
| CVE-2021-42811 | MEDIUM | 6.5 | 0.5% | Jun 10, 2022 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows... |
| CVE-2021-40610 | MEDIUM | 5.4 | 0.4% | Jun 9, 2022 | Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management. |
| CVE-2021-40592 | MEDIUM | 5.5 | 0.8% | Jun 8, 2022 | GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreacha... |
| CVE-2021-35532 | MEDIUM | 6.7 | 0.2% | Jun 7, 2022 | A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerabil... |
| CVE-2021-35531 | MEDIUM | 6.7 | 0.3% | Jun 7, 2022 | Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec... |
| CVE-2021-35530 | MEDIUM | 6.7 | 0.2% | Jun 7, 2022 | A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, ... |
| CVE-2021-42245 | MEDIUM | 6.1 | 0.7% | Jun 6, 2022 | FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sectio... |
| CVE-2021-43271 | MEDIUM | 6.8 | 0.8% | Jun 3, 2022 | Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, a... |
| CVE-2021-42892 | MEDIUM | 4.3 | 0.7% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and p... |
| CVE-2021-38221 | MEDIUM | 5.4 | 0.5% | Jun 2, 2022 | bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS. |
| CVE-2021-43512 | MEDIUM | 5.5 | 0.2% | Jun 2, 2022 | An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cau... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now