2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27503MEDIUM4.8Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: ...
CVE-2021-27499MEDIUM5.9Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: ...
CVE-2021-21866HIGH7.8A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality o...
CVE-2021-21865HIGH7.8A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of ...
CVE-2021-21864HIGH7.8A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionalit...
CVE-2021-37848HIGH7.5common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash ...
CVE-2021-37847HIGH7.5crypto/digest.c in Pengutronix barebox through 2021.07.0 leaks timing information because memcmp is used during digest v...
CVE-2021-35450HIGH7.2A Server Side Template Injection in the Entando Admin Console 6.3.9 and before allows a user with privileges to execute ...
CVE-2021-3673HIGH7.5A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can le...
CVE-2021-37843CRITICAL9.8The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the use...
CVE-2021-33198HIGH7.5In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString o...
CVE-2021-33197MEDIUM5.3In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a ...
CVE-2021-33196HIGH7.5In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a ...
CVE-2021-33195HIGH7.3Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, ...
CVE-2021-32810CRITICAL9.8crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions ...
CVE-2021-32806MEDIUM6.1Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal prior to 1...
CVE-2021-22447HIGH7.5There is an Improper Check for Unusual or Exceptional Conditions Vulnerability in Huawei Smartphone.Successful exploitat...
CVE-2021-22446HIGH7.5There is an Information Disclosure Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may ...
CVE-2021-22445HIGH7.5There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may caus...
CVE-2021-29697MEDIUM4.9IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenti...
CVE-2021-29696HIGH7.2IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenti...
CVE-2021-22444CRITICAL9.8There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may caus...
CVE-2021-22443HIGH7.5There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may caus...
CVE-2021-22442HIGH7.5There is an Improper Validation of Integrity Check Value Vulnerability in Huawei Smartphone.Successful exploitation of t...
CVE-2021-22438CRITICAL9.8There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.Successful exploitation of this vul...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now