2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-20861HIGH8.8Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmwa...
CVE-2021-20860HIGH8.8Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GS...
CVE-2021-20859HIGH8ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmwar...
CVE-2021-20851HIGH8.8Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a re...
CVE-2021-43360HIGH8.8Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restrictio...
CVE-2021-43359HIGH8.8Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page af...
CVE-2021-43358HIGH7.5Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path trav...
CVE-2021-40809HIGH8.8An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in res...
CVE-2021-41256HIGH7.1nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud N...
CVE-2021-36328HIGH8.8Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may ...
CVE-2021-40101HIGH7.2An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a pro...
CVE-2021-43296HIGH7.5Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
CVE-2021-43284HIGH7.8An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its defau...
CVE-2021-43283HIGH8.8An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the ...
CVE-2021-43771HIGH7.8Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulne...
CVE-2021-42123HIGH8.8Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1...
CVE-2021-3725HIGH8.8Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered...
CVE-2021-43790HIGH8.1Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all v...
CVE-2021-44429HIGH7.5Serva 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcod...
CVE-2021-44428HIGH7.5Pinkie 2.15 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcod...
CVE-2021-43786HIGH7.5Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verific...
CVE-2021-43783HIGH8.5@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a...
CVE-2021-34800HIGH7.5Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before...
CVE-2021-44198HIGH7.8DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (W...
CVE-2021-42364HIGH8.8The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_pa...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now