2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40280 | HIGH | 7.2 | 1.1% | Dec 9, 2021 | An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php. |
| CVE-2021-40279 | HIGH | 7.2 | 1.1% | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php. |
| CVE-2021-21955 | HIGH | 7.5 | 1.0% | Dec 9, 2021 | An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary... |
| CVE-2021-21954 | CRITICAL | 9.9 | 2.4% | Dec 9, 2021 | A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of An... |
| CVE-2021-20146 | CRITICAL | 9.8 | 2.0% | Dec 9, 2021 | An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affi... |
| CVE-2021-20145 | HIGH | 7.5 | 1.2% | Dec 9, 2021 | Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon ... |
| CVE-2021-20144 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server ser... |
| CVE-2021-20143 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server ser... |
| CVE-2021-20142 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server ser... |
| CVE-2021-20141 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server ser... |
| CVE-2021-20140 | HIGH | 8.8 | 4.0% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server ser... |
| CVE-2021-20139 | HIGH | 8.8 | 4.0% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server serv... |
| CVE-2021-20138 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web inter... |
| CVE-2021-20137 | MEDIUM | 6.1 | 2.6% | Dec 9, 2021 | A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the... |
| CVE-2021-41449 | HIGH | 7.1 | 1.7% | Dec 9, 2021 | A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote ... |
| CVE-2021-22565 | MEDIUM | 6.5 | 0.4% | Dec 9, 2021 | An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable t... |
| CVE-2021-3817 | CRITICAL | 9.8 | 37.8% | Dec 9, 2021 | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command |
| CVE-2021-43071 | HIGH | 8.8 | 1.2% | Dec 9, 2021 | A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and b... |
| CVE-2021-43068 | HIGH | 8.1 | 0.6% | Dec 9, 2021 | A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authen... |
| CVE-2021-43065 | HIGH | 7.8 | 0.4% | Dec 9, 2021 | A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, ver... |
| CVE-2021-42759 | MEDIUM | 6.7 | 0.3% | Dec 9, 2021 | A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows atta... |
| CVE-2021-36167 | MEDIUM | 5.3 | 0.6% | Dec 9, 2021 | An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 an... |
| CVE-2021-43410 | MEDIUM | 5.3 | 2.4% | Dec 9, 2021 | Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some ... |
| CVE-2021-43204 | MEDIUM | 4.4 | 0.3% | Dec 9, 2021 | A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.... |
| CVE-2021-36194 | HIGH | 8.8 | 1.4% | Dec 9, 2021 | Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now