2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-20474HIGH7.5IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requir...
CVE-2021-20415HIGH7.5IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker...
CVE-2021-20379HIGH7.5IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could all...
CVE-2021-20378HIGH8.8IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an aut...
CVE-2021-33220HIGH7.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.
CVE-2021-33217HIGH8.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Rea...
CVE-2021-31925HIGH7.5Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a d...
CVE-2021-28931HIGH8.8Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /them...
CVE-2021-32532HIGH7.5Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary fi...
CVE-2021-32527HIGH7.5Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files...
CVE-2021-32525HIGH7.2The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control int...
CVE-2021-32524HIGH7.2Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Su...
CVE-2021-32523HIGH7.2Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control...
CVE-2021-32519HIGH7.5Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows re...
CVE-2021-32518HIGH7.5A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbi...
CVE-2021-32517HIGH7.5Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrar...
CVE-2021-32516HIGH7.5Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. ...
CVE-2021-32514HIGH7.5Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and d...
CVE-2021-26274HIGH7.1The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
CVE-2021-26273HIGH7.8The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.
CVE-2021-34622HIGH8.8A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfileP...
CVE-2021-34620HIGH8.8The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Si...
CVE-2021-22555HIGH7.8A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an ...
CVE-2021-26038HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL...
CVE-2021-26036HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now