2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41395MEDIUM6.5Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations...
CVE-2021-41394MEDIUM5.3Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts i...
CVE-2021-41393CRITICAL9.8Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificate...
CVE-2021-3806MEDIUM5.3A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same netw...
CVE-2021-41392CRITICAL9.8static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafte...
CVE-2021-41391MEDIUM5.4In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vul...
CVE-2021-41390HIGH8In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is v...
CVE-2021-41387HIGH8.8seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid ...
CVE-2021-39218MEDIUM6.3Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is ...
CVE-2021-41383HIGH7.2setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters...
CVE-2021-41380MEDIUM6.5RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB proto...
CVE-2021-39219MEDIUM6.3Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusio...
CVE-2021-39216MEDIUM6.3Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 the...
CVE-2021-38412CRITICAL9.8Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Ra...
CVE-2021-38406HIGH7.8Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specif...
CVE-2021-38404HIGH7.8Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specif...
CVE-2021-38402HIGH7.8Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specif...
CVE-2021-41326CRITICAL9.8In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
CVE-2021-40825HIGH8.6nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. T...
CVE-2021-41317CRITICAL9.8XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
CVE-2021-38304HIGH7.8Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged ...
CVE-2021-41316HIGH8.1The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (wit...
CVE-2021-41315HIGH8.8The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows...
CVE-2021-39228CRITICAL9.8Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. Th...
CVE-2021-39227CRITICAL9.8ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge`...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now