2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25389MEDIUM6.1Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authe...
CVE-2021-25388HIGH7.1Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary a...
CVE-2021-25387CRITICAL10An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Relea...
CVE-2021-25386CRITICAL9.8An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-202...
CVE-2021-25385CRITICAL9.8An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-202...
CVE-2021-25384CRITICAL9.8An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor libra...
CVE-2021-25383CRITICAL9.8An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release...
CVE-2021-20396LOW3.3IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can b...
CVE-2021-26996HIGH7.5E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when ...
CVE-2021-26995HIGH8.8E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when ...
CVE-2021-26993MEDIUM5.3E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when ...
CVE-2021-26997MEDIUM6.5E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when ...
CVE-2021-3013CRITICAL9.8ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working direct...
CVE-2021-34540MEDIUM6.1Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.
CVE-2021-33205HIGH8.8Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could lo...
CVE-2021-26829MEDIUM5.4OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
CVE-2021-26828HIGH8.8OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe...
CVE-2021-28814HIGH8.8An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows r...
CVE-2021-28805MEDIUM5.5Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If ...
CVE-2021-28801HIGH7.5An out-of-bounds read vulnerability has been reported to affect certain QNAP switches running QSS. If exploited, this vu...
CVE-2021-24035CRITICAL9.1A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for...
CVE-2021-25684HIGH7.8It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
CVE-2021-25683HIGH7.8It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from t...
CVE-2021-25682HIGH7.8It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from ...
CVE-2021-23393MEDIUM5.4This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possibl...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now