2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-40412HIGH7.2An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_...
CVE-2021-40411HIGH7.2An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40410HIGH7.2An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40407HIGH7.2An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40406HIGH7.5A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0....
CVE-2021-40397HIGH7.8A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-cra...
CVE-2021-40396HIGH8.8A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafte...
CVE-2021-40389HIGH8.8A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-cr...
CVE-2021-40388HIGH8.8A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replac...
CVE-2021-40340HIGH7.5Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server ex...
CVE-2021-40339HIGH7.5Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker th...
CVE-2021-27654HIGH7.8Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
CVE-2021-22827HIGH8.8A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits ...
CVE-2021-22826HIGH8.8A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits ...
CVE-2021-22825HIGH8A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker ...
CVE-2021-22821HIGH8.6A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward req...
CVE-2021-22818HIGH7.5A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to...
CVE-2021-22816HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Servic...
CVE-2021-22808HIGH7.8A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configur...
CVE-2021-22807HIGH7.8A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 con...
CVE-2021-22725HIGH8.8A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or...
CVE-2021-22724HIGH8.8A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or...
CVE-2021-41608HIGH7.5A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a ...
CVE-2021-45897HIGH8.8SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
CVE-2021-42791HIGH7.3An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now