2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0051 | MEDIUM | 4.4 | 0.2% | Jun 9, 2021 | Improper input validation in the Intel(R) SPS versions before SPS_E5_04.04.04.023.0, SPS_E5_04.04.03.228.0 or SPS_SoC-A_... |
| CVE-2021-0001 | MEDIUM | 4.7 | 0.2% | Jun 9, 2021 | Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enab... |
| CVE-2021-33894 | HIGH | 8.8 | 1.1% | Jun 9, 2021 | In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.... |
| CVE-2021-29049 | MEDIUM | 6.1 | 0.8% | Jun 9, 2021 | Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix... |
| CVE-2021-0113 | MEDIUM | 6.5 | 0.4% | Jun 9, 2021 | Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08... |
| CVE-2021-0105 | HIGH | 7.3 | 0.3% | Jun 9, 2021 | Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentia... |
| CVE-2021-0101 | HIGH | 8.8 | 0.4% | Jun 9, 2021 | Buffer overflow in the BMC firmware for Intel(R) Server BoardM10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may ... |
| CVE-2021-0097 | MEDIUM | 6.5 | 0.5% | Jun 9, 2021 | Path traversal in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may ... |
| CVE-2021-0095 | MEDIUM | 4.4 | 0.2% | Jun 9, 2021 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a... |
| CVE-2021-0070 | HIGH | 8.8 | 0.4% | Jun 9, 2021 | Improper input validation in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100... |
| CVE-2021-33833 | CRITICAL | 9.8 | 2.9% | Jun 9, 2021 | ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAM... |
| CVE-2021-33359 | HIGH | 7.5 | 1.3% | Jun 9, 2021 | A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read us... |
| CVE-2021-33358 | HIGH | 8.8 | 2.7% | Jun 9, 2021 | Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in... |
| CVE-2021-33357 | CRITICAL | 9.8 | 17.9% | Jun 9, 2021 | A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the ... |
| CVE-2021-33356 | HIGH | 8.8 | 5.3% | Jun 9, 2021 | Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inj... |
| CVE-2021-32677 | HIGH | 8.1 | 0.8% | Jun 9, 2021 | FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lowe... |
| CVE-2021-32942 | MEDIUM | 5.5 | 0.2% | Jun 9, 2021 | The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowVi... |
| CVE-2021-3196 | HIGH | 8.8 | 1.0% | Jun 9, 2021 | An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. ... |
| CVE-2021-30133 | MEDIUM | 6.1 | 0.8% | Jun 9, 2021 | A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows ... |
| CVE-2021-29995 | HIGH | 8.8 | 4.2% | Jun 9, 2021 | A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute... |
| CVE-2021-23854 | MEDIUM | 6.1 | 0.6% | Jun 9, 2021 | An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in t... |
| CVE-2021-23853 | CRITICAL | 9.8 | 0.9% | Jun 9, 2021 | In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through ... |
| CVE-2021-23852 | MEDIUM | 4.9 | 0.8% | Jun 9, 2021 | An authenticated attacker with administrator rights Bosch IP cameras can call an URL with an invalid parameter that caus... |
| CVE-2021-23848 | MEDIUM | 6.1 | 0.6% | Jun 9, 2021 | An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interfa... |
| CVE-2021-23847 | CRITICAL | 9.1 | 1.4% | Jun 9, 2021 | A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract s... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now