2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22324HIGH7.5There is a Credentials Management Errors vulnerability in Huawei Smartphone. Successful exploitation of this vulnerabili...
CVE-2021-22322HIGH7.5There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of t...
CVE-2021-22317HIGH7.5There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may...
CVE-2021-22316MEDIUM6.8There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical acce...
CVE-2021-22313HIGH7.5There is a Security Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impai...
CVE-2021-22308LOW3.3There is a Business Logic Errors vulnerability in Huawei Smartphone. The malicious apps installed on the device can keep...
CVE-2021-32460HIGH7.8The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability i...
CVE-2021-24023HIGH8.8An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access v...
CVE-2021-20380HIGH7.5IBM QRadar Advisor With Watson App 1.1 through 2.5 as used on IBM QRadar SIEM 7.4 could allow a remote user to obtain se...
CVE-2021-32926HIGH7.5When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the ...
CVE-2021-3569MEDIUM5.5A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. T...
CVE-2021-33806CRITICAL9.8The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data...
CVE-2021-28848HIGH7.5Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window t...
CVE-2021-32923HIGH7.4HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (speci...
CVE-2021-31830MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Se...
CVE-2021-28847HIGH7.5MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change request...
CVE-2021-26584MEDIUM6.1A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scrip...
CVE-2021-22130MEDIUM4.9A stack-based buffer overflow vulnerability in FortiProxy physical appliance CLI 2.0.0 to 2.0.1, 1.2.0 to 1.2.9, 1.1.0 t...
CVE-2021-31831MEDIUM5.5Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote aut...
CVE-2021-33805Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10906. Reason: This candidate is a duplicate of ...
CVE-2021-28812HIGH8.8A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vuln...
CVE-2021-28807MEDIUM5.4A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, t...
CVE-2021-28806MEDIUM5.4A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnera...
CVE-2021-29670MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-29668MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now