2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20852MEDIUM6.8Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02...
CVE-2021-20851HIGH8.8Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a re...
CVE-2021-20847MEDIUM6.1Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, ...
CVE-2021-43360HIGH8.8Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restrictio...
CVE-2021-43359HIGH8.8Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page af...
CVE-2021-43358HIGH7.5Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path trav...
CVE-2021-40809HIGH8.8An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in res...
CVE-2021-41256HIGH7.1nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud N...
CVE-2021-36330CRITICAL9.8Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote ...
CVE-2021-36329MEDIUM6.5Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malici...
CVE-2021-36328HIGH8.8Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may ...
CVE-2021-36327MEDIUM5.3Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unaut...
CVE-2021-36326MEDIUM6.5Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A...
CVE-2021-4026MEDIUM4.3bookstack is vulnerable to Improper Access Control
CVE-2021-43320Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-41244. Reason: This candidate is a reservation d...
CVE-2021-42564MEDIUM5.4An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (wit...
CVE-2021-40101HIGH7.2An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a pro...
CVE-2021-31787MEDIUM6.5The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous un...
CVE-2021-44230MEDIUM6.5PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 databa...
CVE-2021-43319CRITICAL9.8Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validat...
CVE-2021-43296HIGH7.5Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
CVE-2021-43295MEDIUM6.1Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
CVE-2021-43294MEDIUM6.1Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.
CVE-2021-43284HIGH7.8An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its defau...
CVE-2021-43283HIGH8.8An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now