2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45998 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the Loc... |
| CVE-2021-45990 | CRITICAL | 9.8 | 1.9% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2021-45987 | CRITICAL | 9.8 | 1.9% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2021-45986 | CRITICAL | 9.8 | 1.9% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2021-45742 | CRITICAL | 9.8 | 3.1% | Feb 4, 2022 | TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function... |
| CVE-2021-45740 | CRITICAL | 9.8 | 1.3% | Feb 4, 2022 | TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This v... |
| CVE-2021-45738 | CRITICAL | 9.8 | 4.4% | Feb 4, 2022 | TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function Uploa... |
| CVE-2021-45733 | CRITICAL | 9.8 | 4.4% | Feb 4, 2022 | TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSy... |
| CVE-2021-44882 | CRITICAL | 9.8 | 4.8% | Feb 4, 2022 | D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem fu... |
| CVE-2021-44881 | CRITICAL | 9.8 | 4.9% | Feb 4, 2022 | D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the tws... |
| CVE-2021-44880 | CRITICAL | 9.8 | 4.2% | Feb 4, 2022 | D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a ... |
| CVE-2021-44247 | CRITICAL | 9.8 | 2.8% | Feb 4, 2022 | Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were disco... |
| CVE-2021-42640 | CRITICAL | 9.1 | 2.1% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul... |
| CVE-2021-42637 | CRITICAL | 9.8 | 2.3% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server ... |
| CVE-2021-39070 | CRITICAL | 9.8 | 1.8% | Feb 2, 2022 | IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabl... |
| CVE-2021-24043 | CRITICAL | 9.1 | 1.1% | Feb 2, 2022 | A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android ... |
| CVE-2021-46093 | CRITICAL | 9.8 | 1.2% | Feb 1, 2022 | eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. |
| CVE-2021-43510 | CRITICAL | 9.8 | 7.5% | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login... |
| CVE-2021-43509 | CRITICAL | 9.8 | 1.8% | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-se... |
| CVE-2021-24814 | CRITICAL | 9.6 | 2.1% | Feb 1, 2022 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthent... |
| CVE-2021-24762 | CRITICAL | 9.8 | 86.9% | Feb 1, 2022 | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using... |
| CVE-2021-31617 | CRITICAL | 9.8 | 2.1% | Jan 31, 2022 | In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 thro... |
| CVE-2021-23520 | CRITICAL | 9.8 | 1.1% | Jan 31, 2022 | The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) vi... |
| CVE-2021-45079 | CRITICAL | 9.1 | 2.8% | Jan 31, 2022 | In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticat... |
| CVE-2021-46660 | CRITICAL | 9.8 | 1.1% | Jan 30, 2022 | Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now