2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29396CRITICAL9.8Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated ...
CVE-2021-29395HIGH7.5Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 al...
CVE-2021-29394MEDIUM6.5Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 all...
CVE-2021-29393CRITICAL9.8Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allo...
CVE-2021-43635MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malic...
CVE-2021-46398HIGH8.8A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use...
CVE-2021-44978CRITICAL9.8iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code ...
CVE-2021-44977HIGH7.5In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
CVE-2021-44886MEDIUM5.3In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't h...
CVE-2021-43145HIGH8.1With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user acco...
CVE-2021-44983MEDIUM4.9In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Manage...
CVE-2021-46320HIGH7.5In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent exa...
CVE-2021-44903HIGH7.8Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabi...
CVE-2021-44901HIGH7.8Micro-Star International (MSI) Dragon Center <= 2.0.116.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulne...
CVE-2021-44900HIGH7.8Micro-Star International (MSI) App Player <= 4.280.1.6309 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulne...
CVE-2021-44899HIGH7.8Micro-Star International (MSI) Center <= 1.0.31.0 is vulnerable to multiple Privilege Escalation vulnerabilities in the ...
CVE-2021-46457CRITICAL9.8D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgS...
CVE-2021-46456CRITICAL9.8D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetW...
CVE-2021-46455CRITICAL9.8D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetS...
CVE-2021-46454CRITICAL9.8D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetW...
CVE-2021-46453CRITICAL9.8D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetS...
CVE-2021-46452CRITICAL9.8D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetN...
CVE-2021-46233CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_...
CVE-2021-46232CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function vers...
CVE-2021-46231CRITICAL9.8D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now