2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20133MEDIUM6.1Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vuln...
CVE-2021-20132HIGH8.8Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can a...
CVE-2021-45379HIGH8.8Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in ...
CVE-2021-38876MEDIUM6.1IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2021-43862MEDIUM5.4jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31...
CVE-2021-43861MEDIUM5.4Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ...
CVE-2021-45818MEDIUM6.1SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.
CVE-2021-45815MEDIUM6.1Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-45427CRITICAL9.8Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An at...
CVE-2021-4188HIGH7.5mruby is vulnerable to NULL Pointer Dereference
CVE-2021-43876HIGH8.8Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2021-36724MEDIUM5.5ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the sec...
CVE-2021-4187HIGH7.8vim is vulnerable to Use After Free
CVE-2021-45885HIGH7.5An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific upd...
CVE-2021-25993MEDIUM5.4In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged...
CVE-2021-23727HIGH7.5This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result ...
CVE-2021-4176MEDIUM6.1livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4175MEDIUM5.4livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-36723HIGH7.5Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predic...
CVE-2021-36722CRITICAL9.8Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dum...
CVE-2021-38688HIGH7.5An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability...
CVE-2021-38687CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, t...
CVE-2021-38680MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, t...
CVE-2021-35035MEDIUM6.5A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authentic...
CVE-2021-35034CRITICAL9.1An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now