2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33221 | CRITICAL | 9.8 | 57.0% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints. |
| CVE-2021-33220 | HIGH | 7.8 | 0.3% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist. |
| CVE-2021-33219 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Adm... |
| CVE-2021-33218 | CRITICAL | 9.8 | 2.3% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords th... |
| CVE-2021-33217 | HIGH | 8.8 | 1.4% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Rea... |
| CVE-2021-33216 | CRITICAL | 9.8 | 13.8% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowin... |
| CVE-2021-33215 | MEDIUM | 4.3 | 1.2% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal. |
| CVE-2021-31925 | HIGH | 7.5 | 1.3% | Jul 7, 2021 | Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a d... |
| CVE-2021-28931 | HIGH | 8.8 | 1.2% | Jul 7, 2021 | Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /them... |
| CVE-2021-35451 | MEDIUM | 6.1 | 0.8% | Jul 7, 2021 | In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user bro... |
| CVE-2021-32538 | CRITICAL | 9.8 | 2.0% | Jul 7, 2021 | ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers ca... |
| CVE-2021-32537 | MEDIUM | 6.5 | 0.4% | Jul 7, 2021 | Realtek HAD contains a driver crashed vulnerability which allows local side attackers to send a special string to the ke... |
| CVE-2021-32535 | CRITICAL | 9.8 | 1.4% | Jul 7, 2021 | The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain admi... |
| CVE-2021-32534 | CRITICAL | 9.8 | 1.9% | Jul 7, 2021 | QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inj... |
| CVE-2021-32533 | CRITICAL | 9.8 | 1.9% | Jul 7, 2021 | The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject an... |
| CVE-2021-32532 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary fi... |
| CVE-2021-32531 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands w... |
| CVE-2021-32530 | CRITICAL | 9.8 | 2.3% | Jul 7, 2021 | OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arb... |
| CVE-2021-32529 | CRITICAL | 9.8 | 2.3% | Jul 7, 2021 | Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary command... |
| CVE-2021-32528 | MEDIUM | 5.3 | 1.1% | Jul 7, 2021 | Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system inf... |
| CVE-2021-32527 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files... |
| CVE-2021-32526 | MEDIUM | 6.5 | 0.9% | Jul 7, 2021 | Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote ... |
| CVE-2021-32525 | HIGH | 7.2 | 1.7% | Jul 7, 2021 | The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control int... |
| CVE-2021-32524 | HIGH | 7.2 | 1.7% | Jul 7, 2021 | Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Su... |
| CVE-2021-32523 | HIGH | 7.2 | 1.5% | Jul 7, 2021 | Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now