2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37589HIGH7.5Virtua Cobranca before 12R allows SQL Injection on the login page.
CVE-2021-39947HIGH7.5In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2...
CVE-2021-41932HIGH8.8A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to...
CVE-2021-42245MEDIUM6.1FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sectio...
CVE-2021-43271MEDIUM6.8Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, a...
CVE-2021-42893HIGH7.5In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization th...
CVE-2021-42892MEDIUM4.3In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and p...
CVE-2021-42891HIGH7.5In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
CVE-2021-42890CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file...
CVE-2021-42889HIGH7.5In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without author...
CVE-2021-42888CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file ...
CVE-2021-42887CRITICAL9.8In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
CVE-2021-42886HIGH7.5TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib conf...
CVE-2021-42885CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file gl...
CVE-2021-42884CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file g...
CVE-2021-42877HIGH7.5TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_...
CVE-2021-33473CRITICAL9.1An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when...
CVE-2021-42875CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the ...
CVE-2021-45983CRITICAL9.8NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
CVE-2021-45982HIGH8.8NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
CVE-2021-45981CRITICAL9.8NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
CVE-2021-38221MEDIUM5.4bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.
CVE-2021-4014Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-44098CRITICAL9.8EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remot...
CVE-2021-44097CRITICAL9.8EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now