2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44359HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...
CVE-2021-44358HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...
CVE-2021-23760CRITICAL9.8The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow ...
CVE-2021-23558CRITICAL9.8The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Not...
CVE-2021-23484CRITICAL9.8The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can le...
CVE-2021-4034HIGH7.8A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool...
CVE-2021-44463HIGH7.3Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Dis...
CVE-2021-40423HIGH7.5A denial of service vulnerability exists in the cgiserver.cgi API command parser functionality of Reolink RLC-410W v3.0....
CVE-2021-40419HIGH7.5A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-craf...
CVE-2021-40416HIGH8.8An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC...
CVE-2021-40415MEDIUM6.5An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC...
CVE-2021-40414HIGH7.1An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC...
CVE-2021-40413HIGH7.1An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC...
CVE-2021-40412HIGH7.2An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_...
CVE-2021-40411HIGH7.2An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40410HIGH7.2An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40409CRITICAL9.8An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40408CRITICAL9.8An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40407HIGH7.2An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40406HIGH7.5A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0....
CVE-2021-40404MEDIUM6.5An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20...
CVE-2021-40397HIGH7.8A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-cra...
CVE-2021-40396HIGH8.8A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafte...
CVE-2021-40389HIGH8.8A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-cr...
CVE-2021-40388HIGH8.8A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replac...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now