2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34731 | MEDIUM | 4.8 | 0.6% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remo... |
| CVE-2021-34701 | MEDIUM | 4.3 | 1.5% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie... |
| CVE-2021-1500 | MEDIUM | 6.1 | 0.8% | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote a... |
| CVE-2021-42624 | HIGH | 7.8 | 0.3% | Nov 4, 2021 | A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, w... |
| CVE-2021-34597 | HIGH | 7.8 | 0.6% | Nov 4, 2021 | Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an... |
| CVE-2021-34594 | MEDIUM | 6.5 | 1.1% | Nov 4, 2021 | TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.... |
| CVE-2021-41562 | MEDIUM | 6.1 | 0.2% | Nov 3, 2021 | A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue ... |
| CVE-2021-43339 | HIGH | 8.8 | 9.6% | Nov 3, 2021 | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file... |
| CVE-2021-43338 | — | — | — | Nov 3, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43339. Reason: This candidate is a duplicate of ... |
| CVE-2021-43032 | MEDIUM | 4.8 | 0.9% | Nov 3, 2021 | In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertisi... |
| CVE-2021-42772 | CRITICAL | 9.8 | 1.2% | Nov 3, 2021 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly... |
| CVE-2021-41492 | CRITICAL | 9.8 | 1.6% | Nov 3, 2021 | Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Co... |
| CVE-2021-38488 | MEDIUM | 4.8 | 12.3% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-38428 | MEDIUM | 4.8 | 11.4% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-38424 | HIGH | 7.8 | 0.5% | Nov 3, 2021 | The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formula... |
| CVE-2021-38422 | HIGH | 7.8 | 0.2% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attac... |
| CVE-2021-38420 | HIGH | 7.8 | 0.2% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged us... |
| CVE-2021-38418 | MEDIUM | 5.9 | 0.5% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be position... |
| CVE-2021-38416 | HIGH | 7.8 | 0.2% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL ... |
| CVE-2021-38411 | MEDIUM | 4.8 | 0.6% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-38407 | MEDIUM | 4.8 | 0.6% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-38403 | MEDIUM | 4.8 | 0.6% | Nov 3, 2021 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated atta... |
| CVE-2021-35053 | HIGH | 7.5 | 2.5% | Nov 3, 2021 | Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change spe... |
| CVE-2021-33800 | HIGH | 7.5 | 1.5% | Nov 3, 2021 | In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal. |
| CVE-2021-22960 | MEDIUM | 6.5 | 2.3% | Nov 3, 2021 | The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. Th... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now