2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41366HIGH7.8Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
CVE-2021-41356HIGH7.5Windows Denial of Service Vulnerability
CVE-2021-41351MEDIUM4.3Microsoft Edge (Chrome based) Spoofing on IE Mode
CVE-2021-41349MEDIUM6.5Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-40442HIGH7.8Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-38666HIGH8.8Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-38665HIGH7.4Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2021-38631MEDIUM4.4Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-36957HIGH7.8Windows Desktop Bridge Elevation of Privilege Vulnerability
CVE-2021-26444LOW3.3Azure RTOS Information Disclosure Vulnerability
CVE-2021-26443CRITICAL9Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
CVE-2021-37158HIGH8.8An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS c...
CVE-2021-37157HIGH8.8An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root passwo...
CVE-2021-43575MEDIUM5.5KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local use...
CVE-2021-35489MEDIUM6.1Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected...
CVE-2021-35488MEDIUM6.1Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title paramete...
CVE-2021-43572CRITICAL9.8The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to ...
CVE-2021-43571CRITICAL9.8The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-...
CVE-2021-43570CRITICAL9.8The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zer...
CVE-2021-43569CRITICAL9.8The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-z...
CVE-2021-43568CRITICAL9.8The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non...
CVE-2021-20119HIGH7.1The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in us...
CVE-2021-43174HIGH7.5NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP r...
CVE-2021-43173HIGH7.5In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not ans...
CVE-2021-43172HIGH7.5NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to ne...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now