2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25680 | MEDIUM | 6.1 | 3.4% | Apr 20, 2021 | The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These ... |
| CVE-2021-25679 | MEDIUM | 5.4 | 2.9% | Apr 20, 2021 | The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. T... |
| CVE-2021-20453 | HIGH | 8.2 | 2.6% | Apr 20, 2021 | IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when pr... |
| CVE-2021-20023 | MEDIUM | 4.9 | 50.2% | Apr 20, 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an ... |
| CVE-2021-3038 | MEDIUM | 5.5 | 0.2% | Apr 20, 2021 | A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Wind... |
| CVE-2021-3037 | LOW | 2.3 | 0.3% | Apr 20, 2021 | An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection... |
| CVE-2021-3036 | MEDIUM | 4.4 | 0.2% | Apr 20, 2021 | An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN... |
| CVE-2021-3035 | HIGH | 7.2 | 1.3% | Apr 20, 2021 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when proce... |
| CVE-2021-3506 | HIGH | 7.1 | 0.4% | Apr 19, 2021 | An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions... |
| CVE-2021-27458 | HIGH | 7.5 | 1.1% | Apr 19, 2021 | If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All... |
| CVE-2021-20208 | MEDIUM | 6.1 | 0.6% | Apr 19, 2021 | A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a conta... |
| CVE-2021-3505 | MEDIUM | 5.5 | 0.4% | Apr 19, 2021 | A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit stre... |
| CVE-2021-3498 | HIGH | 7.8 | 1.8% | Apr 19, 2021 | GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files. |
| CVE-2021-3497 | HIGH | 7.8 | 1.2% | Apr 19, 2021 | GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska f... |
| CVE-2021-30199 | MEDIUM | 5.5 | 0.9% | Apr 19, 2021 | In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The ... |
| CVE-2021-30022 | MEDIUM | 5.5 | 1.1% | Apr 19, 2021 | There is a integer overflow in media_tools/av_parsers.c in the gf_avc_read_pps_bs_internal in GPAC from 0.5.2 to 1.0.1. ... |
| CVE-2021-30020 | MEDIUM | 5.5 | 0.9% | Apr 19, 2021 | In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers.c in GPAC 1.0.1 there is a loop, which w... |
| CVE-2021-30019 | MEDIUM | 5.5 | 0.9% | Apr 19, 2021 | In the adts_dmx_process function in filters/reframe_adts.c in GPAC 1.0.1, a crafted file may cause ctx->hdr.frame_size t... |
| CVE-2021-30015 | MEDIUM | 5.5 | 0.9% | Apr 19, 2021 | There is a Null Pointer Dereference in function filter_core/filter_pck.c:gf_filter_pck_new_alloc_internal in GPAC 1.0.1.... |
| CVE-2021-30014 | MEDIUM | 5.5 | 1.1% | Apr 19, 2021 | There is a integer overflow in media_tools/av_parsers.c in the hevc_parse_slice_segment function in GPAC from v0.9.0-pre... |
| CVE-2021-29279 | HIGH | 7.8 | 1.0% | Apr 19, 2021 | There is a integer overflow in function filter_core/filter_props.c:gf_props_assign_value in GPAC 1.0.1. In which, the ar... |
| CVE-2021-31262 | MEDIUM | 5.5 | 0.9% | Apr 19, 2021 | The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) ... |
| CVE-2021-31261 | MEDIUM | 5.5 | 1.1% | Apr 19, 2021 | The gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read memory via a crafted file in the MP4Box command. |
| CVE-2021-31260 | MEDIUM | 5.5 | 0.9% | Apr 19, 2021 | The MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a cra... |
| CVE-2021-31259 | MEDIUM | 5.5 | 0.9% | Apr 19, 2021 | The gf_isom_cenc_get_default_info_internal function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL po... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now