2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4177MEDIUM5.3livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2021-20873HIGH8.1Yappli is an application development platform which provides the function to access a requested URL using Custom URL Sch...
CVE-2021-45911HIGH7.8An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attack...
CVE-2021-45910HIGH7.8An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an at...
CVE-2021-45909HIGH7.8An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. ...
CVE-2021-45908HIGH7.8An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has ...
CVE-2021-45907HIGH7.8An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has li...
CVE-2021-45906MEDIUM5.4OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.
CVE-2021-45905MEDIUM5.4OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.
CVE-2021-45904MEDIUM5.4OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.
CVE-2021-45896HIGH8.8Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_we...
CVE-2021-45884HIGH7.5In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fa...
CVE-2021-43858HIGH8.8MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious...
CVE-2021-45895MEDIUM6.1Netgen Tags Bundle 3.4.x before 3.4.11 and 4.0.x before 4.0.15 allows XSS in the Tags Admin interface.
CVE-2021-45890CRITICAL9.8basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.
CVE-2021-4161HIGH7.5The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login ...
CVE-2021-43857HIGH8.8Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code executi...
CVE-2021-43552MEDIUM5.5The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from t...
CVE-2021-43550MEDIUM6.5The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive...
CVE-2021-43548MEDIUM6.5Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrect...
CVE-2021-35232MEDIUM6.1Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with loca...
CVE-2021-33017HIGH8.8The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the prod...
CVE-2021-32993HIGH8.8IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographi...
CVE-2021-23244HIGH7.8ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But s...
CVE-2021-21751HIGH8.1ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and ba...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now