2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27351 | MEDIUM | 5.3 | 0.8% | Feb 19, 2021 | The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and U... |
| CVE-2021-27328 | MEDIUM | 6.5 | 9.0% | Feb 19, 2021 | Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware a... |
| CVE-2021-27214 | MEDIUM | 6.1 | 2.0% | Feb 19, 2021 | A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus ... |
| CVE-2021-23342 | MEDIUM | 6.1 | 1.7% | Feb 19, 2021 | This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execu... |
| CVE-2021-21512 | MEDIUM | 6 | 0.3% | Feb 19, 2021 | Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally auth... |
| CVE-2021-22703 | HIGH | 7.5 | 0.6% | Feb 19, 2021 | A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/... |
| CVE-2021-22702 | HIGH | 7.5 | 0.6% | Feb 19, 2021 | A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/... |
| CVE-2021-22701 | MEDIUM | 4.5 | 0.3% | Feb 19, 2021 | A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION86... |
| CVE-2021-3210 | CRITICAL | 9.6 | 2.7% | Feb 19, 2021 | components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrar... |
| CVE-2021-3204 | MEDIUM | 6.5 | 0.9% | Feb 19, 2021 | SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the ser... |
| CVE-2021-26296 | HIGH | 7.5 | 3.0% | Feb 19, 2021 | In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, ... |
| CVE-2021-3339 | MEDIUM | 4.3 | 1.9% | Feb 19, 2021 | ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the S... |
| CVE-2021-27405 | HIGH | 7.5 | 1.8% | Feb 19, 2021 | A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for N... |
| CVE-2021-26746 | MEDIUM | 6.1 | 1.0% | Feb 19, 2021 | Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI. |
| CVE-2021-27404 | MEDIUM | 6.1 | 0.9% | Feb 19, 2021 | Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header. |
| CVE-2021-27403 | MEDIUM | 6.1 | 1.2% | Feb 19, 2021 | Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS. |
| CVE-2021-26747 | CRITICAL | 9.8 | 53.6% | Feb 18, 2021 | Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading t... |
| CVE-2021-26712 | HIGH | 7.5 | 3.6% | Feb 18, 2021 | Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk ... |
| CVE-2021-26906 | MEDIUM | 5.9 | 2.5% | Feb 18, 2021 | An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0;... |
| CVE-2021-26717 | HIGH | 7.5 | 2.2% | Feb 18, 2021 | An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certifie... |
| CVE-2021-3271 | MEDIUM | 4.8 | 0.9% | Feb 18, 2021 | PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Descriptio... |
| CVE-2021-27335 | CRITICAL | 9.8 | 3.0% | Feb 18, 2021 | KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoseria... |
| CVE-2021-27329 | CRITICAL | 10 | 1.5% | Feb 18, 2021 | Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names. |
| CVE-2021-21318 | MEDIUM | 5.4 | 0.7% | Feb 18, 2021 | Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast b... |
| CVE-2021-27379 | HIGH | 7.8 | 0.4% | Feb 18, 2021 | An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DM... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now