2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37150HIGH7.5Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure ...
CVE-2021-41615CRITICAL9.8websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded...
CVE-2021-28511MEDIUM6.5This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impac...
CVE-2021-46681MEDIUM6.1A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu...
CVE-2021-46680MEDIUM6.1A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu...
CVE-2021-46679MEDIUM6.1A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu...
CVE-2021-46678MEDIUM6.1A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu...
CVE-2021-46677MEDIUM6.1A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu...
CVE-2021-46676MEDIUM6.1A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu...
CVE-2021-36861MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an atta...
CVE-2021-27798MEDIUM5.5A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory ...
CVE-2021-32771HIGH8.1Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to ca...
CVE-2021-43179Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2021-43178Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2021-23385MEDIUM6.1This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect...
CVE-2021-27785MEDIUM5HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerabil...
CVE-2021-3601Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Op...
CVE-2021-39088HIGH7.8IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unkno...
CVE-2021-41556CRITICAL10sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that ca...
CVE-2021-22650CRITICAL9.8An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWin...
CVE-2021-22648CRITICAL9.8Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
CVE-2021-22646CRITICAL9.8The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TB...
CVE-2021-22644CRITICAL9.8Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
CVE-2021-22642HIGH7.5An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
CVE-2021-22640CRITICAL9.8An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now