2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25680MEDIUM6.1The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These ...
CVE-2021-25679MEDIUM5.4The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. T...
CVE-2021-20453HIGH8.2IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when pr...
CVE-2021-20023MEDIUM4.9SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an ...
CVE-2021-3038MEDIUM5.5A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Wind...
CVE-2021-3037LOW2.3An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection...
CVE-2021-3036MEDIUM4.4An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN...
CVE-2021-3035HIGH7.2An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when proce...
CVE-2021-3506HIGH7.1An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions...
CVE-2021-27458HIGH7.5If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All...
CVE-2021-20208MEDIUM6.1A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a conta...
CVE-2021-3505MEDIUM5.5A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit stre...
CVE-2021-3498HIGH7.8GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
CVE-2021-3497HIGH7.8GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska f...
CVE-2021-30199MEDIUM5.5In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The ...
CVE-2021-30022MEDIUM5.5There is a integer overflow in media_tools/av_parsers.c in the gf_avc_read_pps_bs_internal in GPAC from 0.5.2 to 1.0.1. ...
CVE-2021-30020MEDIUM5.5In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers.c in GPAC 1.0.1 there is a loop, which w...
CVE-2021-30019MEDIUM5.5In the adts_dmx_process function in filters/reframe_adts.c in GPAC 1.0.1, a crafted file may cause ctx->hdr.frame_size t...
CVE-2021-30015MEDIUM5.5There is a Null Pointer Dereference in function filter_core/filter_pck.c:gf_filter_pck_new_alloc_internal in GPAC 1.0.1....
CVE-2021-30014MEDIUM5.5There is a integer overflow in media_tools/av_parsers.c in the hevc_parse_slice_segment function in GPAC from v0.9.0-pre...
CVE-2021-29279HIGH7.8There is a integer overflow in function filter_core/filter_props.c:gf_props_assign_value in GPAC 1.0.1. In which, the ar...
CVE-2021-31262MEDIUM5.5The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) ...
CVE-2021-31261MEDIUM5.5The gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read memory via a crafted file in the MP4Box command.
CVE-2021-31260MEDIUM5.5The MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a cra...
CVE-2021-31259MEDIUM5.5The gf_isom_cenc_get_default_info_internal function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL po...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now