2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27247MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tencent WeChat...
CVE-2021-27246HIGH8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch...
CVE-2021-30494MEDIUM5.5Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries...
CVE-2021-30493MEDIUM5.5Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries...
CVE-2021-28098HIGH7.8An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in t...
CVE-2021-27707CRITICAL9.8Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitra...
CVE-2021-27706CRITICAL9.8Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute...
CVE-2021-27705CRITICAL9.8Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitra...
CVE-2021-27608HIGH7.5An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process ...
CVE-2021-27604MEDIUM6.5In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integratio...
CVE-2021-27599MEDIUM6.5SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30...
CVE-2021-27130CRITICAL9.8Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a rev...
CVE-2021-25314HIGH7.8A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability...
CVE-2021-31152HIGH8.8Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can ena...
CVE-2021-29338MEDIUM5.5Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS)....
CVE-2021-28300CRITICAL9.8NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to e...
CVE-2021-27990HIGH7.5Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called ...
CVE-2021-27815MEDIUM5.5NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and ear...
CVE-2021-27288MEDIUM6.1Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting a...
CVE-2021-27114CRITICAL9.8An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment ...
CVE-2021-27113CRITICAL9.8An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const...
CVE-2021-26832MEDIUM6.1Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attac...
CVE-2021-26827HIGH7.5Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Ser...
CVE-2021-26812MEDIUM6.1Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This ...
CVE-2021-26805MEDIUM5.5Buffer Overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now