2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-34589HIGH7.5In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can ...
CVE-2021-34588HIGH8.6In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected ...
CVE-2021-46441HIGH8.8In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" para...
CVE-2021-46421HIGH7.5Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, w...
CVE-2021-46420HIGH7.5Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability,...
CVE-2021-26629HIGH8.8A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the ....
CVE-2021-35250HIGH7.5A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to t...
CVE-2021-4225HIGH8.8The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to u...
CVE-2021-39040HIGH8IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or si...
CVE-2021-25094HIGH8.1The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rog...
CVE-2021-24957HIGH8.8The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a S...
CVE-2021-36460HIGH7.8VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authen...
CVE-2021-45842HIGH7.5It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-210714151...
CVE-2021-45841HIGH8.1In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the ta...
CVE-2021-45836HIGH8.8An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141...
CVE-2021-40680HIGH8.1There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30...
CVE-2021-38886HIGH8.8IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacke...
CVE-2021-32929HIGH8.8All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.
CVE-2021-37740HIGH7.5A denial of service vulnerability exists in MDT's firmware for the KNXnet/IP Secure router SCN-IP100.03 and KNX IP inter...
CVE-2021-43986HIGH7The setup program for the affected product configures its files and folders with full access, which may allow unauthoriz...
CVE-2021-3101HIGH8.8Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow...
CVE-2021-3100HIGH8.8The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM be...
CVE-2021-4096HIGH8.8The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import cla...
CVE-2021-26627HIGH7.5Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerabilit...
CVE-2021-26626HIGH8.8Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the s...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now