2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20708 | HIGH | 7.2 | 1.2% | Apr 26, 2021 | NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm... |
| CVE-2021-20697 | CRITICAL | 9.8 | 1.7% | Apr 26, 2021 | Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to... |
| CVE-2021-20696 | HIGH | 8.8 | 2.4% | Apr 26, 2021 | DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by ... |
| CVE-2021-20695 | HIGH | 8.8 | 1.3% | Apr 26, 2021 | Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allow... |
| CVE-2021-20694 | HIGH | 8.8 | 1.7% | Apr 26, 2021 | Improper access control vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated atta... |
| CVE-2021-20693 | HIGH | 7.5 | 1.1% | Apr 26, 2021 | Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and ear... |
| CVE-2021-20680 | MEDIUM | 6.1 | 0.8% | Apr 26, 2021 | Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP ... |
| CVE-2021-31762 | HIGH | 8.8 | 8.8% | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea... |
| CVE-2021-31761 | CRITICAL | 9.6 | 33.6% | Apr 25, 2021 | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's ru... |
| CVE-2021-31760 | HIGH | 8.8 | 8.5% | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's... |
| CVE-2021-31726 | CRITICAL | 9.8 | 1.8% | Apr 25, 2021 | Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a pay... |
| CVE-2021-31718 | HIGH | 8.8 | 1.0% | Apr 25, 2021 | The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA ... |
| CVE-2021-30502 | CRITICAL | 9.8 | 2.9% | Apr 25, 2021 | The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code all... |
| CVE-2021-31712 | MEDIUM | 5.4 | 0.8% | Apr 24, 2021 | react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decora... |
| CVE-2021-31794 | MEDIUM | 6.1 | 0.7% | Apr 24, 2021 | Settings.aspx?view=About in Directum 5.8.2 allows XSS via the HTTP User-Agent header. |
| CVE-2021-31795 | HIGH | 7 | 0.4% | Apr 24, 2021 | The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allo... |
| CVE-2021-31598 | HIGH | 7.5 | 1.4% | Apr 24, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling whi... |
| CVE-2021-31791 | HIGH | 7.5 | 0.6% | Apr 23, 2021 | In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout o... |
| CVE-2021-31584 | HIGH | 8.8 | 0.9% | Apr 23, 2021 | Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks ... |
| CVE-2021-31583 | MEDIUM | 5.4 | 1.1% | Apr 23, 2021 | Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stor... |
| CVE-2021-29158 | MEDIUM | 4.9 | 0.8% | Apr 23, 2021 | Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control. |
| CVE-2021-25899 | HIGH | 7.5 | 12.2% | Apr 23, 2021 | An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a craft... |
| CVE-2021-25898 | HIGH | 7.5 | 0.9% | Apr 23, 2021 | An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-c... |
| CVE-2021-31780 | HIGH | 7.5 | 1.0% | Apr 23, 2021 | In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure... |
| CVE-2021-29470 | MEDIUM | 6.5 | 1.6% | Apr 23, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now