2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27351MEDIUM5.3The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and U...
CVE-2021-27328MEDIUM6.5Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware a...
CVE-2021-27214MEDIUM6.1A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus ...
CVE-2021-23342MEDIUM6.1This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execu...
CVE-2021-21512MEDIUM6Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally auth...
CVE-2021-22703HIGH7.5A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/...
CVE-2021-22702HIGH7.5A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/...
CVE-2021-22701MEDIUM4.5A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION86...
CVE-2021-3210CRITICAL9.6components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrar...
CVE-2021-3204MEDIUM6.5SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the ser...
CVE-2021-26296HIGH7.5In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, ...
CVE-2021-3339MEDIUM4.3ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the S...
CVE-2021-27405HIGH7.5A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for N...
CVE-2021-26746MEDIUM6.1Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
CVE-2021-27404MEDIUM6.1Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.
CVE-2021-27403MEDIUM6.1Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.
CVE-2021-26747CRITICAL9.8Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading t...
CVE-2021-26712HIGH7.5Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk ...
CVE-2021-26906MEDIUM5.9An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0;...
CVE-2021-26717HIGH7.5An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certifie...
CVE-2021-3271MEDIUM4.8PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Descriptio...
CVE-2021-27335CRITICAL9.8KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoseria...
CVE-2021-27329CRITICAL10Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
CVE-2021-21318MEDIUM5.4Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast b...
CVE-2021-27379HIGH7.8An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DM...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now