2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44359 | HIGH | 7.7 | 1.1% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
| CVE-2021-44358 | HIGH | 7.7 | 1.1% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
| CVE-2021-23760 | CRITICAL | 9.8 | 1.7% | Jan 28, 2022 | The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow ... |
| CVE-2021-23558 | CRITICAL | 9.8 | 1.6% | Jan 28, 2022 | The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Not... |
| CVE-2021-23484 | CRITICAL | 9.8 | 2.1% | Jan 28, 2022 | The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can le... |
| CVE-2021-4034 | HIGH | 7.8 | 94.9% | Jan 28, 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool... |
| CVE-2021-44463 | HIGH | 7.3 | 0.3% | Jan 28, 2022 | Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Dis... |
| CVE-2021-40423 | HIGH | 7.5 | 1.3% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi API command parser functionality of Reolink RLC-410W v3.0.... |
| CVE-2021-40419 | HIGH | 7.5 | 1.2% | Jan 28, 2022 | A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-craf... |
| CVE-2021-40416 | HIGH | 8.8 | 0.9% | Jan 28, 2022 | An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC... |
| CVE-2021-40415 | MEDIUM | 6.5 | 0.8% | Jan 28, 2022 | An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC... |
| CVE-2021-40414 | HIGH | 7.1 | 0.8% | Jan 28, 2022 | An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC... |
| CVE-2021-40413 | HIGH | 7.1 | 0.8% | Jan 28, 2022 | An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC... |
| CVE-2021-40412 | HIGH | 7.2 | 27.5% | Jan 28, 2022 | An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_... |
| CVE-2021-40411 | HIGH | 7.2 | 4.7% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40410 | HIGH | 7.2 | 27.9% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40409 | CRITICAL | 9.8 | 3.7% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40408 | CRITICAL | 9.8 | 3.7% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40407 | HIGH | 7.2 | 47.9% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40406 | HIGH | 7.5 | 1.5% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.... |
| CVE-2021-40404 | MEDIUM | 6.5 | 1.2% | Jan 28, 2022 | An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20... |
| CVE-2021-40397 | HIGH | 7.8 | 0.9% | Jan 28, 2022 | A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-cra... |
| CVE-2021-40396 | HIGH | 8.8 | 0.4% | Jan 28, 2022 | A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafte... |
| CVE-2021-40389 | HIGH | 8.8 | 0.4% | Jan 28, 2022 | A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-cr... |
| CVE-2021-40388 | HIGH | 8.8 | 0.4% | Jan 28, 2022 | A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replac... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now