2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32522 | CRITICAL | 9.8 | 1.4% | Jul 7, 2021 | Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remo... |
| CVE-2021-32521 | CRITICAL | 9.8 | 0.7% | Jul 7, 2021 | Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate ... |
| CVE-2021-32520 | CRITICAL | 9.8 | 1.0% | Jul 7, 2021 | Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials ... |
| CVE-2021-32519 | HIGH | 7.5 | 0.9% | Jul 7, 2021 | Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows re... |
| CVE-2021-32518 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbi... |
| CVE-2021-32517 | HIGH | 7.5 | 1.3% | Jul 7, 2021 | Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrar... |
| CVE-2021-32516 | HIGH | 7.5 | 1.7% | Jul 7, 2021 | Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. ... |
| CVE-2021-32515 | MEDIUM | 5.3 | 0.8% | Jul 7, 2021 | Directory listing vulnerability in share_link in QSAN Storage Manager allows attackers to list arbitrary directories and... |
| CVE-2021-32514 | HIGH | 7.5 | 1.2% | Jul 7, 2021 | Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and d... |
| CVE-2021-32513 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attac... |
| CVE-2021-32512 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated atta... |
| CVE-2021-32511 | MEDIUM | 4.3 | 0.9% | Jul 7, 2021 | QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to ... |
| CVE-2021-32510 | MEDIUM | 4.3 | 0.9% | Jul 7, 2021 | QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers... |
| CVE-2021-32509 | MEDIUM | 6.5 | 1.3% | Jul 7, 2021 | Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers acces... |
| CVE-2021-32508 | MEDIUM | 6.5 | 1.3% | Jul 7, 2021 | Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers acc... |
| CVE-2021-32507 | MEDIUM | 6.5 | 1.3% | Jul 7, 2021 | Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers down... |
| CVE-2021-32506 | MEDIUM | 6.5 | 1.3% | Jul 7, 2021 | Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download... |
| CVE-2021-26274 | HIGH | 7.1 | 0.4% | Jul 7, 2021 | The Agent in NinjaRMM 5.0.909 has Insecure Permissions. |
| CVE-2021-26273 | HIGH | 7.8 | 0.4% | Jul 7, 2021 | The Agent in NinjaRMM 5.0.909 has Incorrect Access Control. |
| CVE-2021-22233 | MEDIUM | 4.3 | 0.8% | Jul 7, 2021 | An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details |
| CVE-2021-36212 | MEDIUM | 6.1 | 0.6% | Jul 7, 2021 | app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view. |
| CVE-2021-34627 | MEDIUM | 4.3 | 0.7% | Jul 7, 2021 | A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-leve... |
| CVE-2021-34626 | MEDIUM | 4.3 | 0.7% | Jul 7, 2021 | A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenti... |
| CVE-2021-34625 | MEDIUM | 5.4 | 0.6% | Jul 7, 2021 | A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authentica... |
| CVE-2021-34624 | CRITICAL | 9.8 | 6.7% | Jul 7, 2021 | A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress Word... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now