2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27822MEDIUM4.8A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System ...
CVE-2021-39274CRITICAL9.8In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing a...
CVE-2021-39273HIGH8.8In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an u...
CVE-2021-36762HIGH7.5An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing...
CVE-2021-31401HIGH7.5An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't...
CVE-2021-27565HIGH7.5The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loo...
CVE-2021-31400HIGH7.5An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-...
CVE-2021-31228HIGH7.5An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query'...
CVE-2021-31227HIGH7.5An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parse...
CVE-2021-31226CRITICAL9.8An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parse...
CVE-2021-32602MEDIUM6.1An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below...
CVE-2021-32588CRITICAL9.8A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 ...
CVE-2021-34749HIGH8.6A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firep...
CVE-2021-34745HIGH7.8A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local us...
CVE-2021-34734MEDIUM6.5A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series ...
CVE-2021-34730CRITICAL9.8A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W ...
CVE-2021-34716HIGH7.2A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communicat...
CVE-2021-34715HIGH7.2A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication...
CVE-2021-1561MEDIUM5.4A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management...
CVE-2021-39270HIGH7.5In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.
CVE-2021-25218HIGH7.5In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named ...
CVE-2021-39286MEDIUM6.1Webrecorder pywb before 2.6.0 allows XSS because it does not ensure that Jinja2 templates are autoescaped.
CVE-2021-37617HIGH7.3The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop...
CVE-2021-39283MEDIUM5.5liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP a...
CVE-2021-39282HIGH7.5Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now