2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25354MEDIUM5.3Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in ...
CVE-2021-25353HIGH7.1Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private fil...
CVE-2021-25352HIGH7.8Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privilege...
CVE-2021-25351LOW2.4Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physical...
CVE-2021-25350LOW3.9Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to...
CVE-2021-25349HIGH7.8Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action wi...
CVE-2021-21783CRITICAL9.8A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially cr...
CVE-2021-22659HIGH8.6Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a special...
CVE-2021-22496HIGH7.5Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3....
CVE-2021-3450HIGH7.4The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. ...
CVE-2021-3449MEDIUM5.9An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv...
CVE-2021-1492HIGH7.1The Duo Authentication Proxy installer prior to 5.2.1 did not properly validate file installation paths. This allows an ...
CVE-2021-29156HIGH7.5ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke...
CVE-2021-26715CRITICAL9.1The OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Server Side Request Forgery (SSRF)...
CVE-2021-20679HIGH7.5Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII ...
CVE-2021-21386CRITICAL9.8APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows ...
CVE-2021-21385HIGH7.4Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. ...
CVE-2021-1423MEDIUM4.4A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated,...
CVE-2021-1418MEDIUM6.5Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms coul...
CVE-2021-1417MEDIUM6.5Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms coul...
CVE-2021-1411CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms coul...
CVE-2021-1381MEDIUM6.1A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthe...
CVE-2021-1376MEDIUM6.7Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catal...
CVE-2021-1375MEDIUM6.7Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catal...
CVE-2021-1374MEDIUM4.8A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software for the Catalyst 9000...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now