2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25372 | MEDIUM | 6.7 | 0.9% | Mar 26, 2021 | An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. |
| CVE-2021-25371 | MEDIUM | 6.7 | 0.8% | Mar 26, 2021 | A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
| CVE-2021-25370 | MEDIUM | 4.4 | 0.9% | Mar 26, 2021 | An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory cor... |
| CVE-2021-25369 | MEDIUM | 5.5 | 1.1% | Mar 26, 2021 | An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel inform... |
| CVE-2021-22886 | MEDIUM | 6.1 | 1.7% | Mar 26, 2021 | Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdo... |
| CVE-2021-29255 | HIGH | 7.5 | 0.6% | Mar 26, 2021 | MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7... |
| CVE-2021-21403 | CRITICAL | 9.8 | 1.4% | Mar 26, 2021 | In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnera... |
| CVE-2021-20289 | MEDIUM | 5.3 | 1.4% | Mar 26, 2021 | A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are retu... |
| CVE-2021-20285 | MEDIUM | 6.6 | 0.8% | Mar 26, 2021 | A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SE... |
| CVE-2021-20284 | MEDIUM | 5.5 | 1.3% | Mar 26, 2021 | A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_s... |
| CVE-2021-20271 | HIGH | 7 | 0.8% | Mar 26, 2021 | A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who ca... |
| CVE-2021-20197 | MEDIUM | 6.3 | 0.3% | Mar 26, 2021 | There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar,... |
| CVE-2021-20193 | LOW | 3.3 | 1.1% | Mar 26, 2021 | A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input ... |
| CVE-2021-1629 | MEDIUM | 6.1 | 1.3% | Mar 26, 2021 | Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users. |
| CVE-2021-1628 | CRITICAL | 9.8 | 1.2% | Mar 26, 2021 | MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component th... |
| CVE-2021-1627 | CRITICAL | 9.8 | 1.0% | Mar 26, 2021 | MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component ... |
| CVE-2021-1626 | CRITICAL | 9.8 | 2.0% | Mar 26, 2021 | MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that m... |
| CVE-2021-3109 | MEDIUM | 4.8 | 0.8% | Mar 26, 2021 | The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context ... |
| CVE-2021-22506 | HIGH | 7.5 | 25.7% | Mar 26, 2021 | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all vers... |
| CVE-2021-3275 | MEDIUM | 6.1 | 1.8% | Mar 26, 2021 | Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless A... |
| CVE-2021-23890 | MEDIUM | 6.5 | 0.9% | Mar 26, 2021 | Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ... |
| CVE-2021-23889 | MEDIUM | 4.8 | 0.5% | Mar 26, 2021 | Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrator... |
| CVE-2021-23888 | MEDIUM | 6.3 | 0.6% | Mar 26, 2021 | Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could ca... |
| CVE-2021-20683 | MEDIUM | 5.4 | 0.7% | Mar 26, 2021 | Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 all... |
| CVE-2021-20682 | HIGH | 7.2 | 2.5% | Mar 26, 2021 | baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS comma... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now