2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20861 | HIGH | 8.8 | 0.4% | Dec 1, 2021 | Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmwa... |
| CVE-2021-20860 | HIGH | 8.8 | 0.5% | Dec 1, 2021 | Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GS... |
| CVE-2021-20859 | HIGH | 8 | 0.5% | Dec 1, 2021 | ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmwar... |
| CVE-2021-20851 | HIGH | 8.8 | 0.8% | Dec 1, 2021 | Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a re... |
| CVE-2021-43360 | HIGH | 8.8 | 2.3% | Dec 1, 2021 | Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restrictio... |
| CVE-2021-43359 | HIGH | 8.8 | 2.4% | Dec 1, 2021 | Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page af... |
| CVE-2021-43358 | HIGH | 7.5 | 2.3% | Dec 1, 2021 | Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path trav... |
| CVE-2021-40809 | HIGH | 8.8 | 1.4% | Dec 1, 2021 | An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in res... |
| CVE-2021-41256 | HIGH | 7.1 | 1.1% | Nov 30, 2021 | nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud N... |
| CVE-2021-36328 | HIGH | 8.8 | 0.8% | Nov 30, 2021 | Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may ... |
| CVE-2021-40101 | HIGH | 7.2 | 2.6% | Nov 30, 2021 | An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a pro... |
| CVE-2021-43296 | HIGH | 7.5 | 2.6% | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. |
| CVE-2021-43284 | HIGH | 7.8 | 0.4% | Nov 30, 2021 | An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its defau... |
| CVE-2021-43283 | HIGH | 8.8 | 5.4% | Nov 30, 2021 | An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the ... |
| CVE-2021-43771 | HIGH | 7.8 | 0.3% | Nov 30, 2021 | Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulne... |
| CVE-2021-42123 | HIGH | 8.8 | 1.0% | Nov 30, 2021 | Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1... |
| CVE-2021-3725 | HIGH | 8.8 | 1.1% | Nov 30, 2021 | Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered... |
| CVE-2021-43790 | HIGH | 8.1 | 1.6% | Nov 30, 2021 | Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all v... |
| CVE-2021-44429 | HIGH | 7.5 | 1.9% | Nov 29, 2021 | Serva 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcod... |
| CVE-2021-44428 | HIGH | 7.5 | 2.9% | Nov 29, 2021 | Pinkie 2.15 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcod... |
| CVE-2021-43786 | HIGH | 7.5 | 2.3% | Nov 29, 2021 | Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verific... |
| CVE-2021-43783 | HIGH | 8.5 | 1.2% | Nov 29, 2021 | @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a... |
| CVE-2021-34800 | HIGH | 7.5 | 1.0% | Nov 29, 2021 | Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before... |
| CVE-2021-44198 | HIGH | 7.8 | 0.2% | Nov 29, 2021 | DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (W... |
| CVE-2021-42364 | HIGH | 8.8 | 0.6% | Nov 29, 2021 | The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_pa... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now