2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20172 | HIGH | 7.8 | 0.3% | Dec 30, 2021 | All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The inst... |
| CVE-2021-20171 | MEDIUM | 5.5 | 0.2% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's a... |
| CVE-2021-20170 | HIGH | 8.8 | 0.5% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to ... |
| CVE-2021-20169 | MEDIUM | 6.8 | 0.2% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communicatio... |
| CVE-2021-20168 | MEDIUM | 6.8 | 0.3% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physic... |
| CVE-2021-20167 | HIGH | 8 | 8.5% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable ... |
| CVE-2021-20166 | HIGH | 8.8 | 2.2% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin end... |
| CVE-2021-20165 | HIGH | 8.8 | 0.6% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of... |
| CVE-2021-20164 | MEDIUM | 4.9 | 0.7% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Use... |
| CVE-2021-20163 | MEDIUM | 4.9 | 0.8% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp u... |
| CVE-2021-20162 | MEDIUM | 4.9 | 0.5% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and passwords are stored in plaint... |
| CVE-2021-20161 | MEDIUM | 6.8 | 0.2% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious ... |
| CVE-2021-20160 | HIGH | 8.8 | 3.1% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the de... |
| CVE-2021-20159 | HIGH | 8.8 | 3.4% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmw... |
| CVE-2021-20158 | CRITICAL | 9.8 | 10.8% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauth... |
| CVE-2021-20157 | HIGH | 7.5 | 1.5% | Dec 30, 2021 | It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative comma... |
| CVE-2021-20156 | MEDIUM | 6.5 | 0.4% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a mali... |
| CVE-2021-20155 | CRITICAL | 9.8 | 1.9% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore devi... |
| CVE-2021-20154 | HIGH | 7.5 | 0.8% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the d... |
| CVE-2021-20153 | MEDIUM | 6.8 | 1.0% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled,... |
| CVE-2021-20152 | MEDIUM | 6.5 | 0.8% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyo... |
| CVE-2021-20151 | CRITICAL | 10 | 1.6% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's manage... |
| CVE-2021-20150 | MEDIUM | 5.3 | 40.1% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authe... |
| CVE-2021-20149 | CRITICAL | 9.8 | 1.4% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default i... |
| CVE-2021-20134 | HIGH | 8.4 | 7.5% | Dec 30, 2021 | Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vuln... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now