2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29449 | HIGH | 7.8 | 1.9% | Apr 14, 2021 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation ... |
| CVE-2021-28157 | HIGH | 7.2 | 0.8% | Apr 14, 2021 | An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an adminis... |
| CVE-2021-28048 | MEDIUM | 6.5 | 0.6% | Apr 14, 2021 | An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows ... |
| CVE-2021-3017 | HIGH | 7.5 | 63.0% | Apr 14, 2021 | The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover creden... |
| CVE-2021-30459 | CRITICAL | 9.8 | 1.9% | Apr 14, 2021 | A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before ... |
| CVE-2021-29654 | HIGH | 7.2 | 2.2% | Apr 14, 2021 | AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administrati... |
| CVE-2021-28484 | HIGH | 7.5 | 1.5% | Apr 14, 2021 | An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK ... |
| CVE-2021-27710 | CRITICAL | 9.8 | 7.9% | Apr 14, 2021 | Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmwar... |
| CVE-2021-26031 | MEDIUM | 5.3 | 1.2% | Apr 14, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an L... |
| CVE-2021-26030 | MEDIUM | 6.1 | 82.4% | Apr 14, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo paramete... |
| CVE-2021-28856 | MEDIUM | 5.5 | 0.9% | Apr 14, 2021 | In Deark before v1.5.8, a specially crafted input file can cause a division by zero in (src/fmtutil.c) because of the va... |
| CVE-2021-28855 | MEDIUM | 5.5 | 0.9% | Apr 14, 2021 | In Deark before 1.5.8, a specially crafted input file can cause a NULL pointer dereference in the dbuf_write function (s... |
| CVE-2021-28826 | HIGH | 7.8 | 0.2% | Apr 14, 2021 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - ... |
| CVE-2021-28825 | HIGH | 7.8 | 0.2% | Apr 14, 2021 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Co... |
| CVE-2021-28060 | MEDIUM | 5.3 | 1.4% | Apr 14, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET request... |
| CVE-2021-27708 | CRITICAL | 9.8 | 7.6% | Apr 14, 2021 | Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmwar... |
| CVE-2021-27260 | LOW | 3.2 | 0.5% | Apr 14, 2021 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt... |
| CVE-2021-27259 | HIGH | 7.8 | 0.4% | Apr 14, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-4... |
| CVE-2021-27258 | CRITICAL | 9.8 | 4.0% | Apr 14, 2021 | This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion ... |
| CVE-2021-27253 | HIGH | 8.8 | 1.1% | Apr 14, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nigh... |
| CVE-2021-27252 | HIGH | 8.8 | 1.1% | Apr 14, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R780... |
| CVE-2021-27251 | HIGH | 8.8 | 0.7% | Apr 14, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nigh... |
| CVE-2021-27250 | MEDIUM | 6.5 | 66.0% | Apr 14, 2021 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li... |
| CVE-2021-27249 | HIGH | 8.8 | 5.1% | Apr 14, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2... |
| CVE-2021-27248 | HIGH | 8.8 | 2.6% | Apr 14, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now