2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36740MEDIUM6.5Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length hea...
CVE-2021-31859HIGH7.8Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by ...
CVE-2021-23407HIGH7.5This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly saniti...
CVE-2021-36716HIGH7.5A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. ...
CVE-2021-22782MEDIUM5.5Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1...
CVE-2021-22781MEDIUM5.5Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1...
CVE-2021-22780HIGH7.1Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1...
CVE-2021-22779CRITICAL9.1Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, i...
CVE-2021-22778HIGH7.1Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1...
CVE-2021-35527HIGH7.5Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attack...
CVE-2021-33213MEDIUM6.5An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated u...
CVE-2021-33212MEDIUM5.4A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows r...
CVE-2021-33211MEDIUM6.5A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated...
CVE-2021-24117MEDIUM4.9In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (adm...
CVE-2021-0654MEDIUM5.5In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This cou...
CVE-2021-0604MEDIUM5.5In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files over Bluetooth due ...
CVE-2021-0603HIGH7.8In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts without permission due t...
CVE-2021-0602HIGH7.8In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users to view and modify Wi...
CVE-2021-0601MEDIUM5.5In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free. This could lead to ...
CVE-2021-0600HIGH7.8In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to impr...
CVE-2021-0599MEDIUM5.5In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadc...
CVE-2021-0597MEDIUM5.5In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names...
CVE-2021-0596HIGH7.5In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check...
CVE-2021-0594HIGH8In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validatio...
CVE-2021-0592HIGH8.8In various functions in WideVine, there are possible out of bounds writes due to improper input validation. This could l...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now