2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34589 | HIGH | 7.5 | 0.9% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can ... |
| CVE-2021-34588 | HIGH | 8.6 | 0.8% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected ... |
| CVE-2021-46441 | HIGH | 8.8 | 31.8% | Apr 27, 2022 | In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" para... |
| CVE-2021-46421 | HIGH | 7.5 | 5.7% | Apr 27, 2022 | Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, w... |
| CVE-2021-46420 | HIGH | 7.5 | 5.5% | Apr 27, 2022 | Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability,... |
| CVE-2021-26629 | HIGH | 8.8 | 1.5% | Apr 26, 2022 | A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .... |
| CVE-2021-35250 | HIGH | 7.5 | 14.4% | Apr 25, 2022 | A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to t... |
| CVE-2021-4225 | HIGH | 8.8 | 1.7% | Apr 25, 2022 | The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to u... |
| CVE-2021-39040 | HIGH | 8 | 0.7% | Apr 25, 2022 | IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or si... |
| CVE-2021-25094 | HIGH | 8.1 | 83.5% | Apr 25, 2022 | The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rog... |
| CVE-2021-24957 | HIGH | 8.8 | 1.3% | Apr 25, 2022 | The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a S... |
| CVE-2021-36460 | HIGH | 7.8 | 0.4% | Apr 25, 2022 | VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authen... |
| CVE-2021-45842 | HIGH | 7.5 | 2.3% | Apr 25, 2022 | It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-210714151... |
| CVE-2021-45841 | HIGH | 8.1 | 8.1% | Apr 25, 2022 | In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the ta... |
| CVE-2021-45836 | HIGH | 8.8 | 2.4% | Apr 25, 2022 | An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141... |
| CVE-2021-40680 | HIGH | 8.1 | 1.3% | Apr 25, 2022 | There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30... |
| CVE-2021-38886 | HIGH | 8.8 | 0.5% | Apr 22, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacke... |
| CVE-2021-32929 | HIGH | 8.8 | 0.4% | Apr 22, 2022 | All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user. |
| CVE-2021-37740 | HIGH | 7.5 | 4.6% | Apr 20, 2022 | A denial of service vulnerability exists in MDT's firmware for the KNXnet/IP Secure router SCN-IP100.03 and KNX IP inter... |
| CVE-2021-43986 | HIGH | 7 | 0.2% | Apr 20, 2022 | The setup program for the affected product configures its files and folders with full access, which may allow unauthoriz... |
| CVE-2021-3101 | HIGH | 8.8 | 0.4% | Apr 19, 2022 | Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow... |
| CVE-2021-3100 | HIGH | 8.8 | 0.4% | Apr 19, 2022 | The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM be... |
| CVE-2021-4096 | HIGH | 8.8 | 0.6% | Apr 19, 2022 | The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import cla... |
| CVE-2021-26627 | HIGH | 7.5 | 1.3% | Apr 19, 2022 | Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerabilit... |
| CVE-2021-26626 | HIGH | 8.8 | 1.2% | Apr 19, 2022 | Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the s... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now