2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40412 | HIGH | 7.2 | 27.5% | Jan 28, 2022 | An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_... |
| CVE-2021-40411 | HIGH | 7.2 | 4.7% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40410 | HIGH | 7.2 | 27.9% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40407 | HIGH | 7.2 | 47.9% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40406 | HIGH | 7.5 | 1.5% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.... |
| CVE-2021-40397 | HIGH | 7.8 | 0.9% | Jan 28, 2022 | A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-cra... |
| CVE-2021-40396 | HIGH | 8.8 | 0.4% | Jan 28, 2022 | A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafte... |
| CVE-2021-40389 | HIGH | 8.8 | 0.4% | Jan 28, 2022 | A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-cr... |
| CVE-2021-40388 | HIGH | 8.8 | 0.4% | Jan 28, 2022 | A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replac... |
| CVE-2021-40340 | HIGH | 7.5 | 0.7% | Jan 28, 2022 | Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server ex... |
| CVE-2021-40339 | HIGH | 7.5 | 0.7% | Jan 28, 2022 | Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker th... |
| CVE-2021-27654 | HIGH | 7.8 | 0.6% | Jan 28, 2022 | Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. |
| CVE-2021-22827 | HIGH | 8.8 | 1.2% | Jan 28, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits ... |
| CVE-2021-22826 | HIGH | 8.8 | 1.2% | Jan 28, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits ... |
| CVE-2021-22825 | HIGH | 8 | 0.8% | Jan 28, 2022 | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker ... |
| CVE-2021-22821 | HIGH | 8.6 | 0.8% | Jan 28, 2022 | A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward req... |
| CVE-2021-22818 | HIGH | 7.5 | 1.0% | Jan 28, 2022 | A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to... |
| CVE-2021-22816 | HIGH | 7.5 | 0.9% | Jan 28, 2022 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Servic... |
| CVE-2021-22808 | HIGH | 7.8 | 0.9% | Jan 28, 2022 | A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configur... |
| CVE-2021-22807 | HIGH | 7.8 | 0.8% | Jan 28, 2022 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 con... |
| CVE-2021-22725 | HIGH | 8.8 | 0.5% | Jan 28, 2022 | A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or... |
| CVE-2021-22724 | HIGH | 8.8 | 0.5% | Jan 28, 2022 | A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or... |
| CVE-2021-41608 | HIGH | 7.5 | 2.0% | Jan 28, 2022 | A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a ... |
| CVE-2021-45897 | HIGH | 8.8 | 4.6% | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution. |
| CVE-2021-42791 | HIGH | 7.3 | 0.6% | Jan 28, 2022 | An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now