2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20708HIGH7.2NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm...
CVE-2021-20697CRITICAL9.8Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to...
CVE-2021-20696HIGH8.8DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by ...
CVE-2021-20695HIGH8.8Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allow...
CVE-2021-20694HIGH8.8Improper access control vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated atta...
CVE-2021-20693HIGH7.5Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and ear...
CVE-2021-20680MEDIUM6.1Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP ...
CVE-2021-31762HIGH8.8Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea...
CVE-2021-31761CRITICAL9.6Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's ru...
CVE-2021-31760HIGH8.8Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's...
CVE-2021-31726CRITICAL9.8Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a pay...
CVE-2021-31718HIGH8.8The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA ...
CVE-2021-30502CRITICAL9.8The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code all...
CVE-2021-31712MEDIUM5.4react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decora...
CVE-2021-31794MEDIUM6.1Settings.aspx?view=About in Directum 5.8.2 allows XSS via the HTTP User-Agent header.
CVE-2021-31795HIGH7The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allo...
CVE-2021-31598HIGH7.5An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling whi...
CVE-2021-31791HIGH7.5In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout o...
CVE-2021-31584HIGH8.8Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks ...
CVE-2021-31583MEDIUM5.4Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stor...
CVE-2021-29158MEDIUM4.9Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
CVE-2021-25899HIGH7.5An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a craft...
CVE-2021-25898HIGH7.5An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-c...
CVE-2021-31780HIGH7.5In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure...
CVE-2021-29470MEDIUM6.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now