2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20172HIGH7.8All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The inst...
CVE-2021-20171MEDIUM5.5Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's a...
CVE-2021-20170HIGH8.8Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to ...
CVE-2021-20169MEDIUM6.8Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communicatio...
CVE-2021-20168MEDIUM6.8Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physic...
CVE-2021-20167HIGH8Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable ...
CVE-2021-20166HIGH8.8Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin end...
CVE-2021-20165HIGH8.8Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of...
CVE-2021-20164MEDIUM4.9Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Use...
CVE-2021-20163MEDIUM4.9Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp u...
CVE-2021-20162MEDIUM4.9Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and passwords are stored in plaint...
CVE-2021-20161MEDIUM6.8Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious ...
CVE-2021-20160HIGH8.8Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the de...
CVE-2021-20159HIGH8.8Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmw...
CVE-2021-20158CRITICAL9.8Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauth...
CVE-2021-20157HIGH7.5It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative comma...
CVE-2021-20156MEDIUM6.5Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a mali...
CVE-2021-20155CRITICAL9.8Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore devi...
CVE-2021-20154HIGH7.5Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the d...
CVE-2021-20153MEDIUM6.8Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled,...
CVE-2021-20152MEDIUM6.5Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyo...
CVE-2021-20151CRITICAL10Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's manage...
CVE-2021-20150MEDIUM5.3Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authe...
CVE-2021-20149CRITICAL9.8Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default i...
CVE-2021-20134HIGH8.4Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vuln...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now