2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25364LOW3.3A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged application...
CVE-2021-25363MEDIUM6.1An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to ac...
CVE-2021-25362MEDIUM6.1An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to dele...
CVE-2021-25361HIGH8.8An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read...
CVE-2021-25360CRITICAL9.8An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers ...
CVE-2021-25359LOW3.3An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without prope...
CVE-2021-25358LOW3.3A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to ac...
CVE-2021-25357MEDIUM5.5A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3....
CVE-2021-25356HIGH8.8An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged appli...
CVE-2021-21728MEDIUM5.3A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker can consum...
CVE-2021-21433HIGH8.8Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution...
CVE-2021-21432MEDIUM6.5Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication...
CVE-2021-20080MEDIUM6.1Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer be...
CVE-2021-20022HIGH7.2SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload a...
CVE-2021-20021CRITICAL9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account ...
CVE-2021-29671LOW3.3IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mechanism when file audit...
CVE-2021-21431HIGH8.1sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions aroun...
CVE-2021-29221HIGH7A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an e...
CVE-2021-25328HIGH8.8Skyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-sta...
CVE-2021-25327MEDIUM6.5Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-r...
CVE-2021-25326MEDIUM5.4Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_ver...
CVE-2021-30458MEDIUM6.1An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikite...
CVE-2021-30159MEDIUM4.3An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended r...
CVE-2021-30156MEDIUM4.3An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can l...
CVE-2021-30155MEDIUM4.3An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now