2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25165 | HIGH | 8.1 | 1.2% | Apr 28, 2021 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.1... |
| CVE-2021-25164 | MEDIUM | 6.5 | 1.3% | Apr 28, 2021 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.1... |
| CVE-2021-25152 | HIGH | 7.2 | 1.2% | Apr 28, 2021 | A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to ... |
| CVE-2021-29482 | HIGH | 7.5 | 1.4% | Apr 28, 2021 | xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvari... |
| CVE-2021-25154 | HIGH | 7.5 | 1.0% | Apr 28, 2021 | A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8... |
| CVE-2021-25153 | HIGH | 8.1 | 1.1% | Apr 28, 2021 | A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. A... |
| CVE-2021-25151 | HIGH | 8.8 | 12.6% | Apr 28, 2021 | A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to ... |
| CVE-2021-23364 | MEDIUM | 5.3 | 2.4% | Apr 28, 2021 | The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) dur... |
| CVE-2021-25147 | HIGH | 8.1 | 1.3% | Apr 28, 2021 | A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) ... |
| CVE-2021-3508 | MEDIUM | 5.5 | 0.8% | Apr 28, 2021 | A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a... |
| CVE-2021-29388 | MEDIUM | 5.4 | 0.5% | Apr 28, 2021 | A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject ... |
| CVE-2021-29387 | MEDIUM | 5.4 | 0.8% | Apr 28, 2021 | Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote... |
| CVE-2021-29159 | MEDIUM | 6.1 | 0.7% | Apr 28, 2021 | A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacke... |
| CVE-2021-22332 | HIGH | 7.5 | 0.7% | Apr 28, 2021 | There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 an... |
| CVE-2021-22331 | HIGH | 7.5 | 0.7% | Apr 28, 2021 | There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs suffic... |
| CVE-2021-22514 | CRITICAL | 9.8 | 2.0% | Apr 28, 2021 | An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9... |
| CVE-2021-22393 | HIGH | 7.5 | 0.7% | Apr 28, 2021 | There is a denial of service vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and ... |
| CVE-2021-22330 | MEDIUM | 6.5 | 0.3% | Apr 28, 2021 | There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when proc... |
| CVE-2021-22327 | MEDIUM | 6.5 | 0.5% | Apr 28, 2021 | There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient... |
| CVE-2021-30169 | HIGH | 7.5 | 1.7% | Apr 28, 2021 | The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s ... |
| CVE-2021-30168 | CRITICAL | 9.8 | 2.1% | Apr 28, 2021 | The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant adminis... |
| CVE-2021-30167 | CRITICAL | 9.8 | 2.4% | Apr 28, 2021 | The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL ... |
| CVE-2021-30166 | HIGH | 7.2 | 3.8% | Apr 28, 2021 | The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers ... |
| CVE-2021-27648 | HIGH | 8.8 | 2.8% | Apr 28, 2021 | Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essent... |
| CVE-2021-31866 | MEDIUM | 5.3 | 1.2% | Apr 28, 2021 | Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by ob... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now