2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-47723HIGH8.8STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with ...
CVE-2021-47719HIGH8.7COMMAX WebViewer ActiveX Control 2.1.4.5 contains a buffer overflow vulnerability that allows attackers to execute arbit...
CVE-2021-47718HIGH7.5OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive ...
CVE-2021-47710HIGH8.7COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentia...
CVE-2021-47709HIGH8.7COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through ...
CVE-2021-47706HIGH8.7COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated...
CVE-2021-47705HIGH8.7COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to e...
CVE-2021-47703HIGH7.2OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate servi...
CVE-2021-47701HIGH8.8OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and...
CVE-2021-4471HIGH8.7TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files...
CVE-2021-4469HIGH8.7Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoin...
CVE-2021-4468HIGH8.7PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authenticatio...
CVE-2021-4467HIGH8.7Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communicati...
CVE-2021-4466HIGH8.7IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-bas...
CVE-2021-4465HIGH8.7ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0....
CVE-2021-4463HIGH8.7Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulne...
CVE-2021-47700HIGH7.8Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/per...
CVE-2021-47693HIGH8.8The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulner...
CVE-2021-22291HIGH8.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT...
CVE-2021-4460HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix UBSAN shift-out-of-bounds warning ...
CVE-2021-26383HIGH7.9Insufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised users...
CVE-2021-25255HIGH7.5Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.
CVE-2021-47663HIGH8.1Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and there...
CVE-2021-47662HIGH7.5Due to missing authorization an unauthenticated remote attacker can cause a DoS attack by connecting via HTTPS and trigg...
CVE-2021-47670HIGH8.8In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calli...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now