2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4469HIGH8.7Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoin...
CVE-2021-4468HIGH8.7PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authenticatio...
CVE-2021-4467HIGH8.7Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communicati...
CVE-2021-4466HIGH8.7IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-bas...
CVE-2021-4465HIGH8.7ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0....
CVE-2021-4464CRITICAL9.3FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based bu...
CVE-2021-4463HIGH8.7Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulne...
CVE-2021-4462CRITICAL9.8Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthentica...
CVE-2021-47698MEDIUM5.4Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core U...
CVE-2021-4461CRITICAL9.3Seeyon Zhiyuan OA Web Application System versions up to and including 7.0 SP1 improperly decode and parse the `enc` para...
CVE-2021-47700HIGH7.8Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/per...
CVE-2021-47699MEDIUM5.4Nagios XI versions prior to 5.8.7 are vulnerable to cross-site scripting (XSS) via the Audit Log page’s Send to NLS form...
CVE-2021-47697MEDIUM5.4Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insuf...
CVE-2021-47696MEDIUM5.4Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID handling. Insufficient ...
CVE-2021-47695MEDIUM5.4Nagios XI versions prior to 5.8.0 are vulnerable to stored cross-site scripting (XSS) via the My Tools page. Insufficien...
CVE-2021-47694MEDIUM6.1The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site...
CVE-2021-47693HIGH8.8The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulner...
CVE-2021-47692Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. It has been identified as a ...
CVE-2021-47691MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site sc...
CVE-2021-47690MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site sc...
CVE-2021-47689MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais a cross-site scripting ...
CVE-2021-43768MEDIUM5.3In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via th...
CVE-2021-22291HIGH8.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT...
CVE-2021-42193MEDIUM6.1nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the prod...
CVE-2021-4460HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix UBSAN shift-out-of-bounds warning ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now