2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36471CRITICAL9.8Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensiti...
CVE-2021-37492HIGH7.5An issue discovered in src/wallet/wallet.cpp in Ravencoin Core 4.3.2.1 and earlier allows attackers to view sensitive in...
CVE-2021-37491HIGH7.5An issue discovered in src/wallet/wallet.cpp in Dogecoin Project Dogecoin Core 1.14.3 and earlier allows attackers to vi...
CVE-2021-31578CRITICAL9.8In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation...
CVE-2021-31577CRITICAL9.8In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalat...
CVE-2021-31576HIGH7.5In Boa, there is a possible information disclosure due to a missing permission check. This could lead to remote informat...
CVE-2021-31575CRITICAL9.8In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2021-31574CRITICAL9.8In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2021-31573CRITICAL9.8In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2021-36226CRITICAL9.8Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
CVE-2021-36225HIGH8.8Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API com...
CVE-2021-36224CRITICAL9.8Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
CVE-2021-37519MEDIUM5.5Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted au...
CVE-2021-37518MEDIUM6.1Universal Cross Site Scripting (UXSS) vulnerability in Vimium Extension 1.66 and earlier allows remote attackers to run ...
CVE-2021-37502MEDIUM5.4Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user nam...
CVE-2021-37501HIGH7.5Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of servic...
CVE-2021-37497CRITICAL9.8SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted...
CVE-2021-37379MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrar...
CVE-2021-37378MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote a...
CVE-2021-37377MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Brik firmware version 7.2.x and earlier allows remote attackers to r...
CVE-2021-37376MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows ...
CVE-2021-37375MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote ...
CVE-2021-37374MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary ...
CVE-2021-37373MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attack...
CVE-2021-37317CRITICAL9.1Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now