2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25165HIGH8.1A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.1...
CVE-2021-25164MEDIUM6.5A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.1...
CVE-2021-25152HIGH7.2A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to ...
CVE-2021-29482HIGH7.5xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvari...
CVE-2021-25154HIGH7.5A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8...
CVE-2021-25153HIGH8.1A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. A...
CVE-2021-25151HIGH8.8A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to ...
CVE-2021-23364MEDIUM5.3The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) dur...
CVE-2021-25147HIGH8.1A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) ...
CVE-2021-3508MEDIUM5.5A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a...
CVE-2021-29388MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject ...
CVE-2021-29387MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote...
CVE-2021-29159MEDIUM6.1A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacke...
CVE-2021-22332HIGH7.5There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 an...
CVE-2021-22331HIGH7.5There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs suffic...
CVE-2021-22514CRITICAL9.8An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9...
CVE-2021-22393HIGH7.5There is a denial of service vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and ...
CVE-2021-22330MEDIUM6.5There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when proc...
CVE-2021-22327MEDIUM6.5There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient...
CVE-2021-30169HIGH7.5The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s ...
CVE-2021-30168CRITICAL9.8The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant adminis...
CVE-2021-30167CRITICAL9.8The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL ...
CVE-2021-30166HIGH7.2The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers ...
CVE-2021-27648HIGH8.8Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essent...
CVE-2021-31866MEDIUM5.3Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by ob...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now