2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36471 | CRITICAL | 9.8 | 1.7% | Feb 7, 2023 | Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensiti... |
| CVE-2021-37492 | HIGH | 7.5 | 0.8% | Feb 7, 2023 | An issue discovered in src/wallet/wallet.cpp in Ravencoin Core 4.3.2.1 and earlier allows attackers to view sensitive in... |
| CVE-2021-37491 | HIGH | 7.5 | 0.9% | Feb 7, 2023 | An issue discovered in src/wallet/wallet.cpp in Dogecoin Project Dogecoin Core 1.14.3 and earlier allows attackers to vi... |
| CVE-2021-31578 | CRITICAL | 9.8 | 1.3% | Feb 6, 2023 | In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation... |
| CVE-2021-31577 | CRITICAL | 9.8 | 1.1% | Feb 6, 2023 | In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalat... |
| CVE-2021-31576 | HIGH | 7.5 | 1.0% | Feb 6, 2023 | In Boa, there is a possible information disclosure due to a missing permission check. This could lead to remote informat... |
| CVE-2021-31575 | CRITICAL | 9.8 | 1.7% | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2021-31574 | CRITICAL | 9.8 | 1.7% | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2021-31573 | CRITICAL | 9.8 | 1.7% | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2021-36226 | CRITICAL | 9.8 | 0.8% | Feb 6, 2023 | Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files. |
| CVE-2021-36225 | HIGH | 8.8 | 1.0% | Feb 6, 2023 | Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API com... |
| CVE-2021-36224 | CRITICAL | 9.8 | 1.2% | Feb 6, 2023 | Western Digital My Cloud devices before OS5 have a nobody account with a blank password. |
| CVE-2021-37519 | MEDIUM | 5.5 | 0.4% | Feb 3, 2023 | Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted au... |
| CVE-2021-37518 | MEDIUM | 6.1 | 0.7% | Feb 3, 2023 | Universal Cross Site Scripting (UXSS) vulnerability in Vimium Extension 1.66 and earlier allows remote attackers to run ... |
| CVE-2021-37502 | MEDIUM | 5.4 | 0.5% | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user nam... |
| CVE-2021-37501 | HIGH | 7.5 | 1.5% | Feb 3, 2023 | Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of servic... |
| CVE-2021-37497 | CRITICAL | 9.8 | 1.3% | Feb 3, 2023 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted... |
| CVE-2021-37379 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrar... |
| CVE-2021-37378 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote a... |
| CVE-2021-37377 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in Teradek Brik firmware version 7.2.x and earlier allows remote attackers to r... |
| CVE-2021-37376 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows ... |
| CVE-2021-37375 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote ... |
| CVE-2021-37374 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary ... |
| CVE-2021-37373 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attack... |
| CVE-2021-37317 | CRITICAL | 9.1 | 1.5% | Feb 3, 2023 | Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now