2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20852 | MEDIUM | 6.8 | 0.5% | Dec 1, 2021 | Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02... |
| CVE-2021-20851 | HIGH | 8.8 | 0.8% | Dec 1, 2021 | Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a re... |
| CVE-2021-20847 | MEDIUM | 6.1 | 0.8% | Dec 1, 2021 | Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, ... |
| CVE-2021-43360 | HIGH | 8.8 | 2.3% | Dec 1, 2021 | Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restrictio... |
| CVE-2021-43359 | HIGH | 8.8 | 2.4% | Dec 1, 2021 | Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page af... |
| CVE-2021-43358 | HIGH | 7.5 | 2.3% | Dec 1, 2021 | Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path trav... |
| CVE-2021-40809 | HIGH | 8.8 | 1.4% | Dec 1, 2021 | An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in res... |
| CVE-2021-41256 | HIGH | 7.1 | 1.1% | Nov 30, 2021 | nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud N... |
| CVE-2021-36330 | CRITICAL | 9.8 | 1.2% | Nov 30, 2021 | Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote ... |
| CVE-2021-36329 | MEDIUM | 6.5 | 0.7% | Nov 30, 2021 | Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malici... |
| CVE-2021-36328 | HIGH | 8.8 | 0.8% | Nov 30, 2021 | Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may ... |
| CVE-2021-36327 | MEDIUM | 5.3 | 1.0% | Nov 30, 2021 | Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unaut... |
| CVE-2021-36326 | MEDIUM | 6.5 | 1.2% | Nov 30, 2021 | Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A... |
| CVE-2021-4026 | MEDIUM | 4.3 | 0.9% | Nov 30, 2021 | bookstack is vulnerable to Improper Access Control |
| CVE-2021-43320 | — | — | — | Nov 30, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-41244. Reason: This candidate is a reservation d... |
| CVE-2021-42564 | MEDIUM | 5.4 | 0.7% | Nov 30, 2021 | An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (wit... |
| CVE-2021-40101 | HIGH | 7.2 | 2.6% | Nov 30, 2021 | An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a pro... |
| CVE-2021-31787 | MEDIUM | 6.5 | 0.5% | Nov 30, 2021 | The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous un... |
| CVE-2021-44230 | MEDIUM | 6.5 | 1.0% | Nov 30, 2021 | PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 databa... |
| CVE-2021-43319 | CRITICAL | 9.8 | 21.4% | Nov 30, 2021 | Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validat... |
| CVE-2021-43296 | HIGH | 7.5 | 2.6% | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. |
| CVE-2021-43295 | MEDIUM | 6.1 | 2.7% | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module. |
| CVE-2021-43294 | MEDIUM | 6.1 | 1.0% | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module. |
| CVE-2021-43284 | HIGH | 7.8 | 0.4% | Nov 30, 2021 | An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its defau... |
| CVE-2021-43283 | HIGH | 8.8 | 5.4% | Nov 30, 2021 | An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now