2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-38523HIGH7.2NETGEAR R6400 devices before 1.0.1.70 are affected by a stack-based buffer overflow by an authenticated user.
CVE-2021-38522HIGH7.2NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.
CVE-2021-38521HIGH7.2Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50, ...
CVE-2021-38520HIGH7.2Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, ...
CVE-2021-38519HIGH7.2Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, ...
CVE-2021-38518HIGH7.2Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120...
CVE-2021-38517HIGH7.2Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before...
CVE-2021-38515HIGH7.5Certain NETGEAR devices are affected by denial of service. This affects R6400v2 before 1.0.4.98, R6700v3 before 1.0.4.98...
CVE-2021-32122HIGH8Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before...
CVE-2021-38512HIGH7.5An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occ...
CVE-2021-38511HIGH7.5An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction ...
CVE-2021-38490HIGH7.5Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-...
CVE-2021-33708HIGH8.8Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privile...
CVE-2021-29296HIGH7.5Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial...
CVE-2021-29295HIGH7.5Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a d...
CVE-2021-29294HIGH7.5Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause...
CVE-2021-28845HIGH7.5Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B...
CVE-2021-38387HIGH7.5In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients enter...
CVE-2021-38386HIGH7.5In Contiki 3.0, a buffer overflow in the Telnet service allows remote attackers to cause a denial of service because the...
CVE-2021-28844HIGH7.5Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B...
CVE-2021-28843HIGH7.5Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B...
CVE-2021-28842HIGH7.5Null Pointer Deference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03...
CVE-2021-28841HIGH7.5Null Pointer Dereference vulnerability in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and...
CVE-2021-21601HIGH7.8Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File ...
CVE-2021-21567HIGH7.8Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated use...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now