2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36740 | MEDIUM | 6.5 | 1.6% | Jul 14, 2021 | Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length hea... |
| CVE-2021-31859 | HIGH | 7.8 | 0.3% | Jul 14, 2021 | Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by ... |
| CVE-2021-23407 | HIGH | 7.5 | 2.0% | Jul 14, 2021 | This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly saniti... |
| CVE-2021-36716 | HIGH | 7.5 | 1.0% | Jul 14, 2021 | A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. ... |
| CVE-2021-22782 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1... |
| CVE-2021-22781 | MEDIUM | 5.5 | 0.2% | Jul 14, 2021 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1... |
| CVE-2021-22780 | HIGH | 7.1 | 0.2% | Jul 14, 2021 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1... |
| CVE-2021-22779 | CRITICAL | 9.1 | 1.0% | Jul 14, 2021 | Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, i... |
| CVE-2021-22778 | HIGH | 7.1 | 0.2% | Jul 14, 2021 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1... |
| CVE-2021-35527 | HIGH | 7.5 | 1.0% | Jul 14, 2021 | Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attack... |
| CVE-2021-33213 | MEDIUM | 6.5 | 1.3% | Jul 14, 2021 | An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated u... |
| CVE-2021-33212 | MEDIUM | 5.4 | 0.7% | Jul 14, 2021 | A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows r... |
| CVE-2021-33211 | MEDIUM | 6.5 | 1.7% | Jul 14, 2021 | A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated... |
| CVE-2021-24117 | MEDIUM | 4.9 | 2.2% | Jul 14, 2021 | In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (adm... |
| CVE-2021-0654 | MEDIUM | 5.5 | 0.3% | Jul 14, 2021 | In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This cou... |
| CVE-2021-0604 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files over Bluetooth due ... |
| CVE-2021-0603 | HIGH | 7.8 | 0.1% | Jul 14, 2021 | In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts without permission due t... |
| CVE-2021-0602 | HIGH | 7.8 | 0.1% | Jul 14, 2021 | In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users to view and modify Wi... |
| CVE-2021-0601 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free. This could lead to ... |
| CVE-2021-0600 | HIGH | 7.8 | 0.4% | Jul 14, 2021 | In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to impr... |
| CVE-2021-0599 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadc... |
| CVE-2021-0597 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names... |
| CVE-2021-0596 | HIGH | 7.5 | 1.1% | Jul 14, 2021 | In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check... |
| CVE-2021-0594 | HIGH | 8 | 1.4% | Jul 14, 2021 | In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validatio... |
| CVE-2021-0592 | HIGH | 8.8 | 1.1% | Jul 14, 2021 | In various functions in WideVine, there are possible out of bounds writes due to improper input validation. This could l... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now