2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-33221CRITICAL9.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
CVE-2021-33220HIGH7.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.
CVE-2021-33219CRITICAL9.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Adm...
CVE-2021-33218CRITICAL9.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords th...
CVE-2021-33217HIGH8.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Rea...
CVE-2021-33216CRITICAL9.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowin...
CVE-2021-33215MEDIUM4.3An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.
CVE-2021-31925HIGH7.5Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a d...
CVE-2021-28931HIGH8.8Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /them...
CVE-2021-35451MEDIUM6.1In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user bro...
CVE-2021-32538CRITICAL9.8ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers ca...
CVE-2021-32537MEDIUM6.5Realtek HAD contains a driver crashed vulnerability which allows local side attackers to send a special string to the ke...
CVE-2021-32535CRITICAL9.8The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain admi...
CVE-2021-32534CRITICAL9.8QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inj...
CVE-2021-32533CRITICAL9.8The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject an...
CVE-2021-32532HIGH7.5Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary fi...
CVE-2021-32531CRITICAL9.8OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands w...
CVE-2021-32530CRITICAL9.8OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arb...
CVE-2021-32529CRITICAL9.8Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary command...
CVE-2021-32528MEDIUM5.3Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system inf...
CVE-2021-32527HIGH7.5Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files...
CVE-2021-32526MEDIUM6.5Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote ...
CVE-2021-32525HIGH7.2The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control int...
CVE-2021-32524HIGH7.2Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Su...
CVE-2021-32523HIGH7.2Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now