2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21415 | HIGH | 7.8 | 2.1% | Apr 29, 2021 | Prisma VS Code a VSCode extension for Prisma schema files. This is a Remote Code Execution Vulnerability that affects al... |
| CVE-2021-30234 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute a... |
| CVE-2021-30233 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arb... |
| CVE-2021-30232 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute ... |
| CVE-2021-30231 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbit... |
| CVE-2021-30230 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execu... |
| CVE-2021-30229 | HIGH | 8.8 | 2.9% | Apr 29, 2021 | The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrar... |
| CVE-2021-30228 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execut... |
| CVE-2021-30227 | MEDIUM | 6.1 | 0.7% | Apr 29, 2021 | Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0. |
| CVE-2021-29350 | HIGH | 7.2 | 1.3% | Apr 29, 2021 | SQL injection in the getip function in conn/function.php in 发货100-设计素材下载系统 1.1 allows remote attackers to inject arbitra... |
| CVE-2021-27802 | — | — | — | Apr 29, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-24177. Reason: This candidate is a duplicate of ... |
| CVE-2021-25812 | CRITICAL | 9.8 | 2.8% | Apr 29, 2021 | Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/... |
| CVE-2021-25811 | HIGH | 7.5 | 1.6% | Apr 29, 2021 | MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. U... |
| CVE-2021-25810 | MEDIUM | 6.1 | 1.1% | Apr 29, 2021 | Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_st... |
| CVE-2021-20294 | HIGH | 7.8 | 3.4% | Apr 29, 2021 | A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a ... |
| CVE-2021-20228 | HIGH | 7.5 | 2.0% | Apr 29, 2021 | A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the... |
| CVE-2021-30224 | HIGH | 8.8 | 0.7% | Apr 29, 2021 | Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary crede... |
| CVE-2021-30219 | MEDIUM | 5.5 | 0.7% | Apr 29, 2021 | samurai 1.2 has a NULL pointer dereference in printstatus() function in build.c via a crafted build file. |
| CVE-2021-30218 | MEDIUM | 5.5 | 0.7% | Apr 29, 2021 | samurai 1.2 has a NULL pointer dereference in writefile() in util.c via a crafted build file. |
| CVE-2021-30027 | MEDIUM | 5.5 | 0.7% | Apr 29, 2021 | md_analyze_line in md4c.c in md4c 0.4.7 allows attackers to trigger use of uninitialized memory, and cause a denial of s... |
| CVE-2021-28899 | HIGH | 7.5 | 1.1% | Apr 29, 2021 | Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaS... |
| CVE-2021-28280 | MEDIUM | 6.1 | 0.7% | Apr 29, 2021 | CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject ar... |
| CVE-2021-27651 | CRITICAL | 9.8 | 53.8% | Apr 29, 2021 | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp... |
| CVE-2021-20095 | — | — | — | Apr 29, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2021-20092 | HIGH | 7.5 | 8.2% | Apr 29, 2021 | The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not pr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now