2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25313MEDIUM6.1A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows r...
CVE-2021-27965CRITICAL9.8The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privileg...
CVE-2021-27964CRITICAL9.8SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con...
CVE-2021-27963HIGH8.2SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous u...
CVE-2021-27314CRITICAL9.8SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL q...
CVE-2021-3404HIGH7.8In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potential...
CVE-2021-3403HIGH7.8In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and...
CVE-2021-25348LOW2.4Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storag...
CVE-2021-25347MEDIUM5.3Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to interce...
CVE-2021-25346CRITICAL9.8A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arb...
CVE-2021-25345MEDIUM5.5Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel pa...
CVE-2021-25344MEDIUM5.5Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to devic...
CVE-2021-25343LOW3.3Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00....
CVE-2021-25342LOW3.3Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of servi...
CVE-2021-25341LOW3.3Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial ...
CVE-2021-25340LOW2.4Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically prox...
CVE-2021-26989MEDIUM6.5Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P9 and 9.8 are susceptible to a vulnerability which co...
CVE-2021-26988LOW3.5Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which co...
CVE-2021-26293CRITICAL9.8An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allo...
CVE-2021-25339MEDIUM5.2Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given ...
CVE-2021-25338MEDIUM5.2Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, give...
CVE-2021-25337HIGH7.1Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted ...
CVE-2021-25336LOW3.3Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows u...
CVE-2021-25335LOW2.5Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows...
CVE-2021-25334MEDIUM5.5Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted app...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now