2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46437MEDIUM4.8An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.
CVE-2021-46436HIGH7.2An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
CVE-2021-43474CRITICAL9.8An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 functio...
CVE-2021-43453CRITICAL9.8A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in p...
CVE-2021-36202HIGH8.8Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to in...
CVE-2021-43432MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in p...
CVE-2021-43430HIGH8.8An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a mal...
CVE-2021-43429HIGH7.5A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a fail...
CVE-2021-43421CRITICAL9.8A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remot...
CVE-2021-46419CRITICAL9.1An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil...
CVE-2021-46418HIGH7.5An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
CVE-2021-46417HIGH7.5Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege...
CVE-2021-46416HIGH8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups acce...
CVE-2021-43138HIGH7.8In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/i...
CVE-2021-41026MEDIUM6.5A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacke...
CVE-2021-32585MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow...
CVE-2021-26116HIGH8.8An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of Fo...
CVE-2021-26113HIGH7.5A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker w...
CVE-2021-26104HIGH7.8Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6....
CVE-2021-22127HIGH8An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x befo...
CVE-2021-44169HIGH8.8A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6...
CVE-2021-43205MEDIUM5.3An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7...
CVE-2021-32593MEDIUM6.5A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN be...
CVE-2021-26114CRITICAL9.8Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may...
CVE-2021-26112CRITICAL9.8Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpret...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now