2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38557 | HIGH | 8.8 | 2.2% | Aug 24, 2021 | raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. ... |
| CVE-2021-38556 | HIGH | 8.8 | 13.0% | Aug 24, 2021 | includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection. |
| CVE-2021-38306 | CRITICAL | 9.8 | 9.0% | Aug 24, 2021 | Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS comma... |
| CVE-2021-37538 | CRITICAL | 9.8 | 74.5% | Aug 24, 2021 | Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthentica... |
| CVE-2021-38613 | CRITICAL | 9.8 | 4.5% | Aug 24, 2021 | The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any co... |
| CVE-2021-38612 | HIGH | 7.5 | 1.7% | Aug 24, 2021 | In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/r... |
| CVE-2021-38611 | CRITICAL | 9.8 | 1.9% | Aug 24, 2021 | A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attac... |
| CVE-2021-36385 | CRITICAL | 9.8 | 2.7% | Aug 24, 2021 | A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary S... |
| CVE-2021-33191 | CRITICAL | 9.8 | 4.0% | Aug 24, 2021 | From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to pat... |
| CVE-2021-23432 | CRITICAL | 9.8 | 0.9% | Aug 24, 2021 | This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge() |
| CVE-2021-23431 | HIGH | 8.8 | 0.4% | Aug 24, 2021 | The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in variou... |
| CVE-2021-23430 | HIGH | 7.5 | 1.8% | Aug 24, 2021 | All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization. |
| CVE-2021-23429 | HIGH | 7.5 | 1.0% | Aug 24, 2021 | All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or white... |
| CVE-2021-23406 | CRITICAL | 9.8 | 2.9% | Aug 24, 2021 | This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC fil... |
| CVE-2021-39602 | MEDIUM | 6.5 | 0.8% | Aug 23, 2021 | A Buffer Overflow vulnerabilty exists in Miniftpd 1.0 in the do_mkd function in the ftpproto.c file, which could let a r... |
| CVE-2021-39599 | MEDIUM | 6.1 | 0.6% | Aug 23, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/s... |
| CVE-2021-36013 | HIGH | 7.8 | 2.0% | Aug 23, 2021 | Adobe Media Encoder version 15.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a special... |
| CVE-2021-28596 | HIGH | 7.8 | 2.3% | Aug 23, 2021 | Adobe Framemaker version 2020.0.1 (and earlier) and 2019.0.8 (and earlier) are affected by an Out-of-bounds Write vulner... |
| CVE-2021-39615 | CRITICAL | 9.8 | 2.2% | Aug 23, 2021 | D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If... |
| CVE-2021-39614 | CRITICAL | 9.8 | 1.7% | Aug 23, 2021 | D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak pass... |
| CVE-2021-39613 | CRITICAL | 9.8 | 1.7% | Aug 23, 2021 | D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user acc... |
| CVE-2021-39609 | MEDIUM | 5.4 | 1.7% | Aug 23, 2021 | Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function. |
| CVE-2021-39608 | HIGH | 7.2 | 46.9% | Aug 23, 2021 | Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a rem... |
| CVE-2021-39158 | HIGH | 8.8 | 0.5% | Aug 23, 2021 | NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exis... |
| CVE-2021-22449 | HIGH | 7.5 | 0.6% | Aug 23, 2021 | There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now