2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21415HIGH7.8Prisma VS Code a VSCode extension for Prisma schema files. This is a Remote Code Execution Vulnerability that affects al...
CVE-2021-30234CRITICAL9.8The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute a...
CVE-2021-30233CRITICAL9.8The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arb...
CVE-2021-30232CRITICAL9.8The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute ...
CVE-2021-30231CRITICAL9.8The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbit...
CVE-2021-30230CRITICAL9.8The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execu...
CVE-2021-30229HIGH8.8The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrar...
CVE-2021-30228CRITICAL9.8The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execut...
CVE-2021-30227MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0.
CVE-2021-29350HIGH7.2SQL injection in the getip function in conn/function.php in 发货100-设计素材下载系统 1.1 allows remote attackers to inject arbitra...
CVE-2021-27802Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-24177. Reason: This candidate is a duplicate of ...
CVE-2021-25812CRITICAL9.8Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/...
CVE-2021-25811HIGH7.5MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. U...
CVE-2021-25810MEDIUM6.1Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_st...
CVE-2021-20294HIGH7.8A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a ...
CVE-2021-20228HIGH7.5A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the...
CVE-2021-30224HIGH8.8Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary crede...
CVE-2021-30219MEDIUM5.5samurai 1.2 has a NULL pointer dereference in printstatus() function in build.c via a crafted build file.
CVE-2021-30218MEDIUM5.5samurai 1.2 has a NULL pointer dereference in writefile() in util.c via a crafted build file.
CVE-2021-30027MEDIUM5.5md_analyze_line in md4c.c in md4c 0.4.7 allows attackers to trigger use of uninitialized memory, and cause a denial of s...
CVE-2021-28899HIGH7.5Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaS...
CVE-2021-28280MEDIUM6.1CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject ar...
CVE-2021-27651CRITICAL9.8In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp...
CVE-2021-20095Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-20092HIGH7.5The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not pr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now