2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22879HIGH8.8Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowi...
CVE-2021-27989MEDIUM5.4Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.a...
CVE-2021-25316LOW3.3A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Serv...
CVE-2021-28797CRITICAL9.8A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. I...
CVE-2021-31162CRITICAL9.8In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the ele...
CVE-2021-24028CRITICAL9.8An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code e...
CVE-2021-29370MEDIUM6.1A UXSS was discovered in the Thanos-Soft Cheetah Browser in Android 1.2.0 due to the inadequate filter of the intent sch...
CVE-2021-3473MEDIUM4.9An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/rest...
CVE-2021-3471Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-3463MEDIUM4.4A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, ...
CVE-2021-3462HIGH7.8A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that...
CVE-2021-3460CRITICAL9.8The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communicat...
CVE-2021-29440HIGH7.2Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrat...
CVE-2021-29439HIGH7.2The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users wi...
CVE-2021-29438MEDIUM5.4The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to ...
CVE-2021-29437MEDIUM6.8ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable ...
CVE-2021-29436HIGH8.1Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In Time Tracker before version...
CVE-2021-29435MEDIUM6.5trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0...
CVE-2021-29428HIGH7.8In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions ...
CVE-2021-29427HIGH7.2In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/...
CVE-2021-28483CRITICAL9Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-28482HIGH8.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-28481CRITICAL9.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-28480CRITICAL9.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-28477HIGH7Visual Studio Code Remote Code Execution Vulnerability

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now