2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32522CRITICAL9.8Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remo...
CVE-2021-32521CRITICAL9.8Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate ...
CVE-2021-32520CRITICAL9.8Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials ...
CVE-2021-32519HIGH7.5Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows re...
CVE-2021-32518HIGH7.5A vulnerability in share_link in QSAN Storage Manager allows remote attackers to create a symbolic link then access arbi...
CVE-2021-32517HIGH7.5Improper access control vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrar...
CVE-2021-32516HIGH7.5Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files. ...
CVE-2021-32515MEDIUM5.3Directory listing vulnerability in share_link in QSAN Storage Manager allows attackers to list arbitrary directories and...
CVE-2021-32514HIGH7.5Improper access control vulnerability in FirmwareUpgrade in QSAN Storage Manager allows remote attackers to reboot and d...
CVE-2021-32513CRITICAL9.8QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attac...
CVE-2021-32512CRITICAL9.8QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated atta...
CVE-2021-32511MEDIUM4.3QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to ...
CVE-2021-32510MEDIUM4.3QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers...
CVE-2021-32509MEDIUM6.5Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers acces...
CVE-2021-32508MEDIUM6.5Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers acc...
CVE-2021-32507MEDIUM6.5Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers down...
CVE-2021-32506MEDIUM6.5Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download...
CVE-2021-26274HIGH7.1The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
CVE-2021-26273HIGH7.8The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.
CVE-2021-22233MEDIUM4.3An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details
CVE-2021-36212MEDIUM6.1app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
CVE-2021-34627MEDIUM4.3A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-leve...
CVE-2021-34626MEDIUM4.3A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenti...
CVE-2021-34625MEDIUM5.4A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authentica...
CVE-2021-34624CRITICAL9.8A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress Word...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now