2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46437 | MEDIUM | 4.8 | 0.5% | Apr 8, 2022 | An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php. |
| CVE-2021-46436 | HIGH | 7.2 | 1.0% | Apr 8, 2022 | An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php. |
| CVE-2021-43474 | CRITICAL | 9.8 | 3.1% | Apr 7, 2022 | An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 functio... |
| CVE-2021-43453 | CRITICAL | 9.8 | 1.2% | Apr 7, 2022 | A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in p... |
| CVE-2021-36202 | HIGH | 8.8 | 0.8% | Apr 7, 2022 | Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to in... |
| CVE-2021-43432 | MEDIUM | 6.1 | 0.8% | Apr 7, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in p... |
| CVE-2021-43430 | HIGH | 8.8 | 1.1% | Apr 7, 2022 | An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a mal... |
| CVE-2021-43429 | HIGH | 7.5 | 0.9% | Apr 7, 2022 | A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a fail... |
| CVE-2021-43421 | CRITICAL | 9.8 | 42.8% | Apr 7, 2022 | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remot... |
| CVE-2021-46419 | CRITICAL | 9.1 | 71.4% | Apr 7, 2022 | An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil... |
| CVE-2021-46418 | HIGH | 7.5 | 23.9% | Apr 7, 2022 | An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts. |
| CVE-2021-46417 | HIGH | 7.5 | 59.8% | Apr 7, 2022 | Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege... |
| CVE-2021-46416 | HIGH | 8.1 | 6.7% | Apr 7, 2022 | Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups acce... |
| CVE-2021-43138 | HIGH | 7.8 | 3.3% | Apr 6, 2022 | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/i... |
| CVE-2021-41026 | MEDIUM | 6.5 | 0.9% | Apr 6, 2022 | A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacke... |
| CVE-2021-32585 | MEDIUM | 6.1 | 0.7% | Apr 6, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow... |
| CVE-2021-26116 | HIGH | 8.8 | 0.6% | Apr 6, 2022 | An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of Fo... |
| CVE-2021-26113 | HIGH | 7.5 | 0.4% | Apr 6, 2022 | A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker w... |
| CVE-2021-26104 | HIGH | 7.8 | 3.2% | Apr 6, 2022 | Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.... |
| CVE-2021-22127 | HIGH | 8 | 0.5% | Apr 6, 2022 | An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x befo... |
| CVE-2021-44169 | HIGH | 8.8 | 0.4% | Apr 6, 2022 | A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6... |
| CVE-2021-43205 | MEDIUM | 5.3 | 0.9% | Apr 6, 2022 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7... |
| CVE-2021-32593 | MEDIUM | 6.5 | 0.5% | Apr 6, 2022 | A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN be... |
| CVE-2021-26114 | CRITICAL | 9.8 | 1.5% | Apr 6, 2022 | Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may... |
| CVE-2021-26112 | CRITICAL | 9.8 | 1.6% | Apr 6, 2022 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpret... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now