2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34862 | HIGH | 8.8 | 0.8% | Oct 25, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2... |
| CVE-2021-34861 | HIGH | 8.8 | 0.8% | Oct 25, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2... |
| CVE-2021-34859 | HIGH | 8.8 | 9.1% | Oct 25, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer 15.16.8.0. ... |
| CVE-2021-34857 | HIGH | 8.8 | 0.3% | Oct 25, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (... |
| CVE-2021-34856 | HIGH | 8.8 | 0.3% | Oct 25, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (... |
| CVE-2021-34854 | HIGH | 7.8 | 0.2% | Oct 25, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (... |
| CVE-2021-37624 | HIGH | 7.5 | 3.5% | Oct 25, 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2021-24774 | HIGH | 7.2 | 1.3% | Oct 25, 2021 | The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameter... |
| CVE-2021-24769 | HIGH | 7.2 | 1.3% | Oct 25, 2021 | The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before us... |
| CVE-2021-24662 | HIGH | 7.2 | 1.3% | Oct 25, 2021 | The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it ... |
| CVE-2021-24487 | HIGH | 8.8 | 0.6% | Oct 25, 2021 | The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Dis... |
| CVE-2021-0936 | HIGH | 7.8 | 0.1% | Oct 25, 2021 | In acc_read of f_accessory.c, there is a possible memory corruption due to a use after free. This could lead to local es... |
| CVE-2021-0631 | HIGH | 7.5 | 0.9% | Oct 25, 2021 | In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of serv... |
| CVE-2021-0630 | HIGH | 7.5 | 0.9% | Oct 25, 2021 | In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of serv... |
| CVE-2021-40527 | HIGH | 7.5 | 0.7% | Oct 25, 2021 | Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and in... |
| CVE-2021-21703 | HIGH | 7 | 1.3% | Oct 25, 2021 | In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI w... |
| CVE-2021-42840 | HIGH | 8.8 | 58.9% | Oct 22, 2021 | SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta... |
| CVE-2021-41171 | HIGH | 8.8 | 1.9% | Oct 22, 2021 | eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it al... |
| CVE-2021-42836 | HIGH | 7.5 | 2.2% | Oct 22, 2021 | GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack. |
| CVE-2021-42542 | HIGH | 8.8 | 1.4% | Oct 22, 2021 | The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure. |
| CVE-2021-42540 | HIGH | 8.8 | 1.0% | Oct 22, 2021 | The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can l... |
| CVE-2021-42539 | HIGH | 8.8 | 0.7% | Oct 22, 2021 | The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to acco... |
| CVE-2021-42538 | HIGH | 8.8 | 0.9% | Oct 22, 2021 | The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontr... |
| CVE-2021-38485 | HIGH | 8.8 | 0.9% | Oct 22, 2021 | The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide... |
| CVE-2021-30359 | HIGH | 7.8 | 3.9% | Oct 22, 2021 | The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps duri... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now