2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38524 | MEDIUM | 4.9 | 0.9% | Aug 11, 2021 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects MK62 before... |
| CVE-2021-38523 | HIGH | 7.2 | 0.8% | Aug 11, 2021 | NETGEAR R6400 devices before 1.0.1.70 are affected by a stack-based buffer overflow by an authenticated user. |
| CVE-2021-38522 | HIGH | 7.2 | 1.2% | Aug 11, 2021 | NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user. |
| CVE-2021-38521 | HIGH | 7.2 | 0.9% | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50, ... |
| CVE-2021-38520 | HIGH | 7.2 | 1.5% | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, ... |
| CVE-2021-38519 | HIGH | 7.2 | 1.4% | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, ... |
| CVE-2021-38518 | HIGH | 7.2 | 1.4% | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120... |
| CVE-2021-38517 | HIGH | 7.2 | 0.8% | Aug 11, 2021 | Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before... |
| CVE-2021-38516 | CRITICAL | 9.8 | 1.3% | Aug 11, 2021 | Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48... |
| CVE-2021-38515 | HIGH | 7.5 | 1.2% | Aug 11, 2021 | Certain NETGEAR devices are affected by denial of service. This affects R6400v2 before 1.0.4.98, R6700v3 before 1.0.4.98... |
| CVE-2021-38514 | LOW | 2.7 | 0.7% | Aug 11, 2021 | Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72... |
| CVE-2021-38513 | CRITICAL | 9.8 | 1.8% | Aug 11, 2021 | Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.10.11, RBR850 before 3.2.1... |
| CVE-2021-32122 | HIGH | 8 | 0.4% | Aug 11, 2021 | Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before... |
| CVE-2021-38512 | HIGH | 7.5 | 1.8% | Aug 10, 2021 | An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occ... |
| CVE-2021-38511 | HIGH | 7.5 | 1.4% | Aug 10, 2021 | An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction ... |
| CVE-2021-29400 | MEDIUM | 6.5 | 0.6% | Aug 10, 2021 | A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote a... |
| CVE-2021-20032 | CRITICAL | 9.8 | 2.0% | Aug 10, 2021 | SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vul... |
| CVE-2021-38490 | HIGH | 7.5 | 1.0% | Aug 10, 2021 | Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-... |
| CVE-2021-37425 | CRITICAL | 9.1 | 66.3% | Aug 10, 2021 | Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workfl... |
| CVE-2021-37391 | MEDIUM | 5.4 | 2.1% | Aug 10, 2021 | A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator... |
| CVE-2021-37390 | MEDIUM | 6.1 | 0.8% | Aug 10, 2021 | A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature)... |
| CVE-2021-37389 | MEDIUM | 6.1 | 1.0% | Aug 10, 2021 | Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter. |
| CVE-2021-33708 | HIGH | 8.8 | 0.9% | Aug 10, 2021 | Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privile... |
| CVE-2021-29296 | HIGH | 7.5 | 1.1% | Aug 10, 2021 | Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial... |
| CVE-2021-29295 | HIGH | 7.5 | 1.1% | Aug 10, 2021 | Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a d... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now