2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29449HIGH7.8Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation ...
CVE-2021-28157HIGH7.2An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an adminis...
CVE-2021-28048MEDIUM6.5An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows ...
CVE-2021-3017HIGH7.5The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover creden...
CVE-2021-30459CRITICAL9.8A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before ...
CVE-2021-29654HIGH7.2AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administrati...
CVE-2021-28484HIGH7.5An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK ...
CVE-2021-27710CRITICAL9.8Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmwar...
CVE-2021-26031MEDIUM5.3An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an L...
CVE-2021-26030MEDIUM6.1An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo paramete...
CVE-2021-28856MEDIUM5.5In Deark before v1.5.8, a specially crafted input file can cause a division by zero in (src/fmtutil.c) because of the va...
CVE-2021-28855MEDIUM5.5In Deark before 1.5.8, a specially crafted input file can cause a NULL pointer dereference in the dbuf_write function (s...
CVE-2021-28826HIGH7.8The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - ...
CVE-2021-28825HIGH7.8The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Co...
CVE-2021-28060MEDIUM5.3A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET request...
CVE-2021-27708CRITICAL9.8Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmwar...
CVE-2021-27260LOW3.2This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt...
CVE-2021-27259HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-4...
CVE-2021-27258CRITICAL9.8This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion ...
CVE-2021-27253HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nigh...
CVE-2021-27252HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R780...
CVE-2021-27251HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nigh...
CVE-2021-27250MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li...
CVE-2021-27249HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2...
CVE-2021-27248HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now