2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27247 | MEDIUM | 6.5 | 6.4% | Apr 14, 2021 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tencent WeChat... |
| CVE-2021-27246 | HIGH | 8 | 6.6% | Apr 14, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch... |
| CVE-2021-30494 | MEDIUM | 5.5 | 0.5% | Apr 14, 2021 | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries... |
| CVE-2021-30493 | MEDIUM | 5.5 | 0.5% | Apr 14, 2021 | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries... |
| CVE-2021-28098 | HIGH | 7.8 | 0.4% | Apr 14, 2021 | An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in t... |
| CVE-2021-27707 | CRITICAL | 9.8 | 2.8% | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitra... |
| CVE-2021-27706 | CRITICAL | 9.8 | 2.8% | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute... |
| CVE-2021-27705 | CRITICAL | 9.8 | 2.9% | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitra... |
| CVE-2021-27608 | HIGH | 7.5 | 0.2% | Apr 14, 2021 | An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process ... |
| CVE-2021-27604 | MEDIUM | 6.5 | 0.8% | Apr 14, 2021 | In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integratio... |
| CVE-2021-27599 | MEDIUM | 6.5 | 0.8% | Apr 14, 2021 | SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30... |
| CVE-2021-27130 | CRITICAL | 9.8 | 2.2% | Apr 14, 2021 | Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a rev... |
| CVE-2021-25314 | HIGH | 7.8 | 0.4% | Apr 14, 2021 | A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability... |
| CVE-2021-31152 | HIGH | 8.8 | 3.8% | Apr 14, 2021 | Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can ena... |
| CVE-2021-29338 | MEDIUM | 5.5 | 1.6% | Apr 14, 2021 | Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS).... |
| CVE-2021-28300 | CRITICAL | 9.8 | 2.1% | Apr 14, 2021 | NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to e... |
| CVE-2021-27990 | HIGH | 7.5 | 1.5% | Apr 14, 2021 | Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called ... |
| CVE-2021-27815 | MEDIUM | 5.5 | 1.3% | Apr 14, 2021 | NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and ear... |
| CVE-2021-27288 | MEDIUM | 6.1 | 0.9% | Apr 14, 2021 | Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting a... |
| CVE-2021-27114 | CRITICAL | 9.8 | 24.6% | Apr 14, 2021 | An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment ... |
| CVE-2021-27113 | CRITICAL | 9.8 | 3.5% | Apr 14, 2021 | An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2021-26832 | MEDIUM | 6.1 | 0.8% | Apr 14, 2021 | Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attac... |
| CVE-2021-26827 | HIGH | 7.5 | 1.7% | Apr 14, 2021 | Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Ser... |
| CVE-2021-26812 | MEDIUM | 6.1 | 97.5% | Apr 14, 2021 | Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This ... |
| CVE-2021-26805 | MEDIUM | 5.5 | 0.7% | Apr 14, 2021 | Buffer Overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now