2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20133 | MEDIUM | 6.1 | 2.1% | Dec 30, 2021 | Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vuln... |
| CVE-2021-20132 | HIGH | 8.8 | 4.3% | Dec 30, 2021 | Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can a... |
| CVE-2021-45379 | HIGH | 8.8 | 1.0% | Dec 30, 2021 | Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in ... |
| CVE-2021-38876 | MEDIUM | 6.1 | 0.6% | Dec 30, 2021 | IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2021-43862 | MEDIUM | 5.4 | 1.0% | Dec 30, 2021 | jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31... |
| CVE-2021-43861 | MEDIUM | 5.4 | 0.9% | Dec 30, 2021 | Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ... |
| CVE-2021-45818 | MEDIUM | 6.1 | 0.6% | Dec 30, 2021 | SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting. |
| CVE-2021-45815 | MEDIUM | 6.1 | 0.6% | Dec 30, 2021 | Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability. |
| CVE-2021-45427 | CRITICAL | 9.8 | 19.0% | Dec 30, 2021 | Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An at... |
| CVE-2021-4188 | HIGH | 7.5 | 0.8% | Dec 30, 2021 | mruby is vulnerable to NULL Pointer Dereference |
| CVE-2021-43876 | HIGH | 8.8 | 1.9% | Dec 29, 2021 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2021-36724 | MEDIUM | 5.5 | 0.2% | Dec 29, 2021 | ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the sec... |
| CVE-2021-4187 | HIGH | 7.8 | 1.6% | Dec 29, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-45885 | HIGH | 7.5 | 0.9% | Dec 29, 2021 | An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific upd... |
| CVE-2021-25993 | MEDIUM | 5.4 | 0.6% | Dec 29, 2021 | In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged... |
| CVE-2021-23727 | HIGH | 7.5 | 3.9% | Dec 29, 2021 | This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result ... |
| CVE-2021-4176 | MEDIUM | 6.1 | 0.8% | Dec 29, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4175 | MEDIUM | 5.4 | 0.5% | Dec 29, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-36723 | HIGH | 7.5 | 0.5% | Dec 29, 2021 | Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predic... |
| CVE-2021-36722 | CRITICAL | 9.8 | 1.3% | Dec 29, 2021 | Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dum... |
| CVE-2021-38688 | HIGH | 7.5 | 0.8% | Dec 29, 2021 | An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability... |
| CVE-2021-38687 | CRITICAL | 9.8 | 1.3% | Dec 29, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, t... |
| CVE-2021-38680 | MEDIUM | 6.1 | 0.7% | Dec 29, 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, t... |
| CVE-2021-35035 | MEDIUM | 6.5 | 0.6% | Dec 29, 2021 | A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authentic... |
| CVE-2021-35034 | CRITICAL | 9.1 | 1.0% | Dec 29, 2021 | An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now