2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20474 | HIGH | 7.5 | 0.5% | Jul 7, 2021 | IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requir... |
| CVE-2021-20415 | HIGH | 7.5 | 0.9% | Jul 7, 2021 | IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker... |
| CVE-2021-20379 | HIGH | 7.5 | 0.5% | Jul 7, 2021 | IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could all... |
| CVE-2021-20378 | HIGH | 8.8 | 0.4% | Jul 7, 2021 | IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an aut... |
| CVE-2021-33220 | HIGH | 7.8 | 0.3% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist. |
| CVE-2021-33217 | HIGH | 8.8 | 1.4% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Rea... |
| CVE-2021-31925 | HIGH | 7.5 | 1.3% | Jul 7, 2021 | Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a d... |
| CVE-2021-28931 | HIGH | 8.8 | 1.2% | Jul 7, 2021 | Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /them... |
| CVE-2021-32532 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary fi... |
| CVE-2021-32527 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files... |
| CVE-2021-32525 | HIGH | 7.2 | 1.7% | Jul 7, 2021 | The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control int... |
| CVE-2021-32524 | HIGH | 7.2 | 1.7% | Jul 7, 2021 | Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Su... |
| CVE-2021-32523 | HIGH | 7.2 | 1.5% | Jul 7, 2021 | Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control... |
| CVE-2021-32519 | HIGH | 7.5 | 0.9% | Jul 7, 2021 | Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows re... |
| CVE-2021-32518 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbi... |
| CVE-2021-32517 | HIGH | 7.5 | 1.3% | Jul 7, 2021 | Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrar... |
| CVE-2021-32516 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. ... |
| CVE-2021-32514 | HIGH | 7.5 | 1.2% | Jul 7, 2021 | Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and d... |
| CVE-2021-26274 | HIGH | 7.1 | 0.4% | Jul 7, 2021 | The Agent in NinjaRMM 5.0.909 has Insecure Permissions. |
| CVE-2021-26273 | HIGH | 7.8 | 0.4% | Jul 7, 2021 | The Agent in NinjaRMM 5.0.909 has Incorrect Access Control. |
| CVE-2021-34622 | HIGH | 8.8 | 4.1% | Jul 7, 2021 | A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfileP... |
| CVE-2021-34620 | HIGH | 8.8 | 2.6% | Jul 7, 2021 | The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Si... |
| CVE-2021-22555 | HIGH | 7.8 | 78.7% | Jul 7, 2021 | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an ... |
| CVE-2021-26038 | HIGH | 7.5 | 1.2% | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL... |
| CVE-2021-26036 | HIGH | 7.5 | 1.4% | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now