2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40280HIGH7.2An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.
CVE-2021-40279HIGH7.2An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.
CVE-2021-21955HIGH7.5An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary...
CVE-2021-21954CRITICAL9.9A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of An...
CVE-2021-20146CRITICAL9.8An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affi...
CVE-2021-20145HIGH7.5Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon ...
CVE-2021-20144HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server ser...
CVE-2021-20143HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server ser...
CVE-2021-20142HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server ser...
CVE-2021-20141HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server ser...
CVE-2021-20140HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server ser...
CVE-2021-20139HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server serv...
CVE-2021-20138HIGH8.8An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web inter...
CVE-2021-20137MEDIUM6.1A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the...
CVE-2021-41449HIGH7.1A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote ...
CVE-2021-22565MEDIUM6.5An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable t...
CVE-2021-3817CRITICAL9.8wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
CVE-2021-43071HIGH8.8A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and b...
CVE-2021-43068HIGH8.1A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authen...
CVE-2021-43065HIGH7.8A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, ver...
CVE-2021-42759MEDIUM6.7A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows atta...
CVE-2021-36167MEDIUM5.3An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 an...
CVE-2021-43410MEDIUM5.3Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some ...
CVE-2021-43204MEDIUM4.4A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6....
CVE-2021-36194HIGH8.8Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now