2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38557HIGH8.8raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. ...
CVE-2021-38556HIGH8.8includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.
CVE-2021-38306CRITICAL9.8Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS comma...
CVE-2021-37538CRITICAL9.8Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthentica...
CVE-2021-38613CRITICAL9.8The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any co...
CVE-2021-38612HIGH7.5In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/r...
CVE-2021-38611CRITICAL9.8A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attac...
CVE-2021-36385CRITICAL9.8A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary S...
CVE-2021-33191CRITICAL9.8From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to pat...
CVE-2021-23432CRITICAL9.8This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
CVE-2021-23431HIGH8.8The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in variou...
CVE-2021-23430HIGH7.5All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.
CVE-2021-23429HIGH7.5All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or white...
CVE-2021-23406CRITICAL9.8This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC fil...
CVE-2021-39602MEDIUM6.5A Buffer Overflow vulnerabilty exists in Miniftpd 1.0 in the do_mkd function in the ftpproto.c file, which could let a r...
CVE-2021-39599MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/s...
CVE-2021-36013HIGH7.8Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a special...
CVE-2021-28596HIGH7.8Adobe Framemaker version 2020.0.1 (and earlier) and 2019.0.8 (and earlier) are affected by an Out-of-bounds Write vulner...
CVE-2021-39615CRITICAL9.8D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If...
CVE-2021-39614CRITICAL9.8D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak pass...
CVE-2021-39613CRITICAL9.8D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user acc...
CVE-2021-39609MEDIUM5.4Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
CVE-2021-39608HIGH7.2Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a rem...
CVE-2021-39158HIGH8.8NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exis...
CVE-2021-22449HIGH7.5There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now