2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0051MEDIUM4.4Improper input validation in the Intel(R) SPS versions before SPS_E5_04.04.04.023.0, SPS_E5_04.04.03.228.0 or SPS_SoC-A_...
CVE-2021-0001MEDIUM4.7Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enab...
CVE-2021-33894HIGH8.8In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2....
CVE-2021-29049MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix...
CVE-2021-0113MEDIUM6.5Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08...
CVE-2021-0105HIGH7.3Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentia...
CVE-2021-0101HIGH8.8Buffer overflow in the BMC firmware for Intel(R) Server BoardM10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may ...
CVE-2021-0097MEDIUM6.5Path traversal in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may ...
CVE-2021-0095MEDIUM4.4Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a...
CVE-2021-0070HIGH8.8Improper input validation in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100...
CVE-2021-33833CRITICAL9.8ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAM...
CVE-2021-33359HIGH7.5A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read us...
CVE-2021-33358HIGH8.8Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in...
CVE-2021-33357CRITICAL9.8A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the ...
CVE-2021-33356HIGH8.8Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inj...
CVE-2021-32677HIGH8.1FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lowe...
CVE-2021-32942MEDIUM5.5The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowVi...
CVE-2021-3196HIGH8.8An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. ...
CVE-2021-30133MEDIUM6.1A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows ...
CVE-2021-29995HIGH8.8A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute...
CVE-2021-23854MEDIUM6.1An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in t...
CVE-2021-23853CRITICAL9.8In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through ...
CVE-2021-23852MEDIUM4.9An authenticated attacker with administrator rights Bosch IP cameras can call an URL with an invalid parameter that caus...
CVE-2021-23848MEDIUM6.1An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interfa...
CVE-2021-23847CRITICAL9.1A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract s...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now