2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20156 | MEDIUM | 6.5 | 0.4% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a mali... |
| CVE-2021-20153 | MEDIUM | 6.8 | 1.0% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled,... |
| CVE-2021-20152 | MEDIUM | 6.5 | 0.8% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyo... |
| CVE-2021-20150 | MEDIUM | 5.3 | 40.1% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authe... |
| CVE-2021-20133 | MEDIUM | 6.1 | 2.1% | Dec 30, 2021 | Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vuln... |
| CVE-2021-38876 | MEDIUM | 6.1 | 0.6% | Dec 30, 2021 | IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2021-43862 | MEDIUM | 5.4 | 1.0% | Dec 30, 2021 | jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31... |
| CVE-2021-43861 | MEDIUM | 5.4 | 0.9% | Dec 30, 2021 | Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ... |
| CVE-2021-45818 | MEDIUM | 6.1 | 0.6% | Dec 30, 2021 | SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting. |
| CVE-2021-45815 | MEDIUM | 6.1 | 0.6% | Dec 30, 2021 | Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability. |
| CVE-2021-36724 | MEDIUM | 5.5 | 0.2% | Dec 29, 2021 | ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the sec... |
| CVE-2021-25993 | MEDIUM | 5.4 | 0.6% | Dec 29, 2021 | In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged... |
| CVE-2021-4176 | MEDIUM | 6.1 | 0.8% | Dec 29, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4175 | MEDIUM | 5.4 | 0.5% | Dec 29, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-38680 | MEDIUM | 6.1 | 0.7% | Dec 29, 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, t... |
| CVE-2021-35035 | MEDIUM | 6.5 | 0.6% | Dec 29, 2021 | A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authentic... |
| CVE-2021-25990 | MEDIUM | 5.4 | 0.6% | Dec 29, 2021 | In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading... |
| CVE-2021-25989 | MEDIUM | 5.4 | 0.6% | Dec 29, 2021 | In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be e... |
| CVE-2021-25988 | MEDIUM | 5.4 | 0.6% | Dec 29, 2021 | In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can b... |
| CVE-2021-44832 | MEDIUM | 6.6 | 97.9% | Dec 28, 2021 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r... |
| CVE-2021-45813 | MEDIUM | 6.1 | 0.6% | Dec 28, 2021 | SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's ses... |
| CVE-2021-45812 | MEDIUM | 6.1 | 0.8% | Dec 28, 2021 | NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can ste... |
| CVE-2021-45903 | MEDIUM | 6.1 | 1.1% | Dec 28, 2021 | A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x bef... |
| CVE-2021-45425 | MEDIUM | 6.1 | 3.4% | Dec 28, 2021 | Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip... |
| CVE-2021-40579 | MEDIUM | 6.5 | 0.8% | Dec 28, 2021 | https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected b... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now