2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20174 | HIGH | 7.5 | 0.6% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default... |
| CVE-2021-20173 | HIGH | 8.8 | 3.2% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the devi... |
| CVE-2021-20172 | HIGH | 7.8 | 0.3% | Dec 30, 2021 | All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The inst... |
| CVE-2021-20170 | HIGH | 8.8 | 0.5% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to ... |
| CVE-2021-20167 | HIGH | 8 | 8.5% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable ... |
| CVE-2021-20166 | HIGH | 8.8 | 2.2% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin end... |
| CVE-2021-20165 | HIGH | 8.8 | 0.6% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of... |
| CVE-2021-20160 | HIGH | 8.8 | 3.1% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the de... |
| CVE-2021-20159 | HIGH | 8.8 | 3.4% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmw... |
| CVE-2021-20157 | HIGH | 7.5 | 1.5% | Dec 30, 2021 | It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative comma... |
| CVE-2021-20154 | HIGH | 7.5 | 0.8% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the d... |
| CVE-2021-20134 | HIGH | 8.4 | 7.5% | Dec 30, 2021 | Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vuln... |
| CVE-2021-20132 | HIGH | 8.8 | 4.3% | Dec 30, 2021 | Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can a... |
| CVE-2021-45379 | HIGH | 8.8 | 1.0% | Dec 30, 2021 | Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in ... |
| CVE-2021-4188 | HIGH | 7.5 | 0.8% | Dec 30, 2021 | mruby is vulnerable to NULL Pointer Dereference |
| CVE-2021-43876 | HIGH | 8.8 | 1.9% | Dec 29, 2021 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2021-4187 | HIGH | 7.8 | 1.6% | Dec 29, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-45885 | HIGH | 7.5 | 0.9% | Dec 29, 2021 | An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific upd... |
| CVE-2021-23727 | HIGH | 7.5 | 3.9% | Dec 29, 2021 | This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result ... |
| CVE-2021-36723 | HIGH | 7.5 | 0.5% | Dec 29, 2021 | Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predic... |
| CVE-2021-38688 | HIGH | 7.5 | 0.8% | Dec 29, 2021 | An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability... |
| CVE-2021-25991 | HIGH | 7.3 | 0.8% | Dec 29, 2021 | In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins ... |
| CVE-2021-44161 | HIGH | 8.8 | 0.5% | Dec 29, 2021 | Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input... |
| CVE-2021-44160 | HIGH | 7.3 | 1.1% | Dec 29, 2021 | Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire anoth... |
| CVE-2021-43556 | HIGH | 7.8 | 2.1% | Dec 28, 2021 | FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing projec... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now