2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22879 | HIGH | 8.8 | 4.7% | Apr 14, 2021 | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowi... |
| CVE-2021-27989 | MEDIUM | 5.4 | 0.5% | Apr 14, 2021 | Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.a... |
| CVE-2021-25316 | LOW | 3.3 | 0.3% | Apr 14, 2021 | A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Serv... |
| CVE-2021-28797 | CRITICAL | 9.8 | 5.9% | Apr 14, 2021 | A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. I... |
| CVE-2021-31162 | CRITICAL | 9.8 | 2.9% | Apr 14, 2021 | In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the ele... |
| CVE-2021-24028 | CRITICAL | 9.8 | 1.7% | Apr 14, 2021 | An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code e... |
| CVE-2021-29370 | MEDIUM | 6.1 | 0.7% | Apr 13, 2021 | A UXSS was discovered in the Thanos-Soft Cheetah Browser in Android 1.2.0 due to the inadequate filter of the intent sch... |
| CVE-2021-3473 | MEDIUM | 4.9 | 0.5% | Apr 13, 2021 | An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/rest... |
| CVE-2021-3471 | — | — | — | Apr 13, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2021-3463 | MEDIUM | 4.4 | 0.2% | Apr 13, 2021 | A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, ... |
| CVE-2021-3462 | HIGH | 7.8 | 0.2% | Apr 13, 2021 | A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that... |
| CVE-2021-3460 | CRITICAL | 9.8 | 0.6% | Apr 13, 2021 | The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communicat... |
| CVE-2021-29440 | HIGH | 7.2 | 30.6% | Apr 13, 2021 | Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrat... |
| CVE-2021-29439 | HIGH | 7.2 | 2.6% | Apr 13, 2021 | The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users wi... |
| CVE-2021-29438 | MEDIUM | 5.4 | 0.7% | Apr 13, 2021 | The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to ... |
| CVE-2021-29437 | MEDIUM | 6.8 | 0.8% | Apr 13, 2021 | ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable ... |
| CVE-2021-29436 | HIGH | 8.1 | 0.5% | Apr 13, 2021 | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In Time Tracker before version... |
| CVE-2021-29435 | MEDIUM | 6.5 | 0.7% | Apr 13, 2021 | trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0... |
| CVE-2021-29428 | HIGH | 7.8 | 0.5% | Apr 13, 2021 | In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions ... |
| CVE-2021-29427 | HIGH | 7.2 | 1.3% | Apr 13, 2021 | In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/... |
| CVE-2021-28483 | CRITICAL | 9 | 1.2% | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-28482 | HIGH | 8.8 | 83.3% | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-28481 | CRITICAL | 9.8 | 36.5% | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-28480 | CRITICAL | 9.8 | 71.4% | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-28477 | HIGH | 7 | 2.3% | Apr 13, 2021 | Visual Studio Code Remote Code Execution Vulnerability |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now