2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34731MEDIUM4.8A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remo...
CVE-2021-34701MEDIUM4.3A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...
CVE-2021-1500MEDIUM6.1A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote a...
CVE-2021-42624HIGH7.8A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, w...
CVE-2021-34597HIGH7.8Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an...
CVE-2021-34594MEDIUM6.5TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2....
CVE-2021-41562MEDIUM6.1A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue ...
CVE-2021-43339HIGH8.8In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file...
CVE-2021-43338Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43339. Reason: This candidate is a duplicate of ...
CVE-2021-43032MEDIUM4.8In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertisi...
CVE-2021-42772CRITICAL9.8Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly...
CVE-2021-41492CRITICAL9.8Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Co...
CVE-2021-38488MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-38428MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-38424HIGH7.8The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formula...
CVE-2021-38422HIGH7.8Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attac...
CVE-2021-38420HIGH7.8Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged us...
CVE-2021-38418MEDIUM5.9Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be position...
CVE-2021-38416HIGH7.8Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL ...
CVE-2021-38411MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-38407MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-38403MEDIUM4.8Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta...
CVE-2021-35053HIGH7.5Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change spe...
CVE-2021-33800HIGH7.5In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
CVE-2021-22960MEDIUM6.5The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. Th...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now