2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-20174HIGH7.5Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default...
CVE-2021-20173HIGH8.8Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the devi...
CVE-2021-20172HIGH7.8All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The inst...
CVE-2021-20170HIGH8.8Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to ...
CVE-2021-20167HIGH8Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable ...
CVE-2021-20166HIGH8.8Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin end...
CVE-2021-20165HIGH8.8Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of...
CVE-2021-20160HIGH8.8Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the de...
CVE-2021-20159HIGH8.8Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmw...
CVE-2021-20157HIGH7.5It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative comma...
CVE-2021-20154HIGH7.5Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the d...
CVE-2021-20134HIGH8.4Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vuln...
CVE-2021-20132HIGH8.8Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can a...
CVE-2021-45379HIGH8.8Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in ...
CVE-2021-4188HIGH7.5mruby is vulnerable to NULL Pointer Dereference
CVE-2021-43876HIGH8.8Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2021-4187HIGH7.8vim is vulnerable to Use After Free
CVE-2021-45885HIGH7.5An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific upd...
CVE-2021-23727HIGH7.5This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result ...
CVE-2021-36723HIGH7.5Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predic...
CVE-2021-38688HIGH7.5An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability...
CVE-2021-25991HIGH7.3In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins ...
CVE-2021-44161HIGH8.8Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input...
CVE-2021-44160HIGH7.3Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire anoth...
CVE-2021-43556HIGH7.8FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing projec...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now