2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37589 | HIGH | 7.5 | 29.7% | Jun 7, 2022 | Virtua Cobranca before 12R allows SQL Injection on the login page. |
| CVE-2021-39947 | HIGH | 7.5 | 0.8% | Jun 6, 2022 | In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2... |
| CVE-2021-41932 | HIGH | 8.8 | 1.0% | Jun 6, 2022 | A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to... |
| CVE-2021-42245 | MEDIUM | 6.1 | 0.7% | Jun 6, 2022 | FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sectio... |
| CVE-2021-43271 | MEDIUM | 6.8 | 0.8% | Jun 3, 2022 | Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, a... |
| CVE-2021-42893 | HIGH | 7.5 | 1.4% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization th... |
| CVE-2021-42892 | MEDIUM | 4.3 | 0.7% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and p... |
| CVE-2021-42891 | HIGH | 7.5 | 1.4% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization. |
| CVE-2021-42890 | CRITICAL | 9.8 | 1.9% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file... |
| CVE-2021-42889 | HIGH | 7.5 | 1.4% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without author... |
| CVE-2021-42888 | CRITICAL | 9.8 | 1.9% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file ... |
| CVE-2021-42887 | CRITICAL | 9.8 | 42.9% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. |
| CVE-2021-42886 | HIGH | 7.5 | 2.0% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib conf... |
| CVE-2021-42885 | CRITICAL | 9.8 | 2.5% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file gl... |
| CVE-2021-42884 | CRITICAL | 9.8 | 2.5% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file g... |
| CVE-2021-42877 | HIGH | 7.5 | 2.3% | Jun 2, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_... |
| CVE-2021-33473 | CRITICAL | 9.1 | 1.0% | Jun 2, 2022 | An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when... |
| CVE-2021-42875 | CRITICAL | 9.8 | 5.0% | Jun 2, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the ... |
| CVE-2021-45983 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution. |
| CVE-2021-45982 | HIGH | 8.8 | 0.9% | Jun 2, 2022 | NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. |
| CVE-2021-45981 | CRITICAL | 9.8 | 1.0% | Jun 2, 2022 | NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. |
| CVE-2021-38221 | MEDIUM | 5.4 | 0.5% | Jun 2, 2022 | bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS. |
| CVE-2021-4014 | — | — | — | Jun 2, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-44098 | CRITICAL | 9.8 | 1.4% | Jun 2, 2022 | EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remot... |
| CVE-2021-44097 | CRITICAL | 9.8 | 1.4% | Jun 2, 2022 | EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now