2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-47712HIGH7.5A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through exi...
CVE-2021-47711HIGH8.8A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via onli...
CVE-2021-47731CRITICAL9.8Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configura...
CVE-2021-47730HIGH8.8Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create admin...
CVE-2021-47729MEDIUM5.4Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that a...
CVE-2021-47728CRITICAL9.8Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remo...
CVE-2021-47727MEDIUM5.3Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live vid...
CVE-2021-47724MEDIUM6.5STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary fi...
CVE-2021-47723HIGH8.8STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with ...
CVE-2021-47719HIGH8.7COMMAX WebViewer ActiveX Control 2.1.4.5 contains a buffer overflow vulnerability that allows attackers to execute arbit...
CVE-2021-47718HIGH7.5OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive ...
CVE-2021-47717MEDIUM6.9IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumera...
CVE-2021-47710HIGH8.7COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentia...
CVE-2021-47709HIGH8.7COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through ...
CVE-2021-47708CRITICAL9.3COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authenticatio...
CVE-2021-47707CRITICAL9.3COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclos...
CVE-2021-47706HIGH8.7COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated...
CVE-2021-47705HIGH8.7COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to e...
CVE-2021-47704MEDIUM6.5OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries ...
CVE-2021-47703HIGH7.2OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate servi...
CVE-2021-47702MEDIUM4.3OpenBMCS 2.4 contains a CSRF vulnerability that allows attackers to perform actions with administrative privileges by ex...
CVE-2021-47701HIGH8.8OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and...
CVE-2021-4472MEDIUM6.5The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' featur...
CVE-2021-4471HIGH8.7TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files...
CVE-2021-4470CRITICAL9.3TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now