2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38524MEDIUM4.9Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects MK62 before...
CVE-2021-38523HIGH7.2NETGEAR R6400 devices before 1.0.1.70 are affected by a stack-based buffer overflow by an authenticated user.
CVE-2021-38522HIGH7.2NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.
CVE-2021-38521HIGH7.2Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50, ...
CVE-2021-38520HIGH7.2Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, ...
CVE-2021-38519HIGH7.2Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, ...
CVE-2021-38518HIGH7.2Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120...
CVE-2021-38517HIGH7.2Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before...
CVE-2021-38516CRITICAL9.8Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48...
CVE-2021-38515HIGH7.5Certain NETGEAR devices are affected by denial of service. This affects R6400v2 before 1.0.4.98, R6700v3 before 1.0.4.98...
CVE-2021-38514LOW2.7Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72...
CVE-2021-38513CRITICAL9.8Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.10.11, RBR850 before 3.2.1...
CVE-2021-32122HIGH8Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before...
CVE-2021-38512HIGH7.5An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occ...
CVE-2021-38511HIGH7.5An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction ...
CVE-2021-29400MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote a...
CVE-2021-20032CRITICAL9.8SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vul...
CVE-2021-38490HIGH7.5Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-...
CVE-2021-37425CRITICAL9.1Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workfl...
CVE-2021-37391MEDIUM5.4A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator...
CVE-2021-37390MEDIUM6.1A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature)...
CVE-2021-37389MEDIUM6.1Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
CVE-2021-33708HIGH8.8Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privile...
CVE-2021-29296HIGH7.5Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial...
CVE-2021-29295HIGH7.5Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a d...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now