2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-34862HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2...
CVE-2021-34861HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2...
CVE-2021-34859HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer 15.16.8.0. ...
CVE-2021-34857HIGH8.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (...
CVE-2021-34856HIGH8.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (...
CVE-2021-34854HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (...
CVE-2021-37624HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2021-24774HIGH7.2The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameter...
CVE-2021-24769HIGH7.2The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before us...
CVE-2021-24662HIGH7.2The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it ...
CVE-2021-24487HIGH8.8The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Dis...
CVE-2021-0936HIGH7.8In acc_read of f_accessory.c, there is a possible memory corruption due to a use after free. This could lead to local es...
CVE-2021-0631HIGH7.5In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of serv...
CVE-2021-0630HIGH7.5In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of serv...
CVE-2021-40527HIGH7.5Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and in...
CVE-2021-21703HIGH7In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI w...
CVE-2021-42840HIGH8.8SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta...
CVE-2021-41171HIGH8.8eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it al...
CVE-2021-42836HIGH7.5GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
CVE-2021-42542HIGH8.8The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.
CVE-2021-42540HIGH8.8The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can l...
CVE-2021-42539HIGH8.8The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to acco...
CVE-2021-42538HIGH8.8The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontr...
CVE-2021-38485HIGH8.8The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide...
CVE-2021-30359HIGH7.8The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps duri...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now