2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44749CRITICAL9.6A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to caus...
CVE-2021-44748MEDIUM6.1A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerab...
CVE-2021-46704CRITICAL9.8In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping ...
CVE-2021-46703CRITICAL9.8In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .N...
CVE-2021-46384CRITICAL9.8https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The at...
CVE-2021-46353MEDIUM5.3An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacke...
CVE-2021-44827HIGH8.8There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devi...
CVE-2021-40846HIGH7.5An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and reque...
CVE-2021-32008HIGH8.7This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname ...
CVE-2021-27756HIGH7.5"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled...
CVE-2021-43590MEDIUM6Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password st...
CVE-2021-3737HIGH7.5A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote att...
CVE-2021-3656HIGH8.8A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMC...
CVE-2021-27757HIGH7.5" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might...
CVE-2021-3575HIGH7.8A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k...
CVE-2021-3428MEDIUM5.5A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a craf...
CVE-2021-20319HIGH7.8An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation im...
CVE-2021-20303MEDIUM6.1A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted fil...
CVE-2021-20302MEDIUM5.5A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single...
CVE-2021-20300MEDIUM5.5A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who...
CVE-2021-46382MEDIUM6.1Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session h...
CVE-2021-46381HIGH7.5Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]...
CVE-2021-46380Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: Reason: This is a duplicate to CVE-2022-22511 Notes
CVE-2021-46379MEDIUM6.1DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust...
CVE-2021-3744MEDIUM5.5A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now