2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20410 | MEDIUM | 5.3 | 0.6% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an... |
| CVE-2021-20409 | HIGH | 7.5 | 0.9% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, cau... |
| CVE-2021-20408 | MEDIUM | 5.5 | 0.2% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to... |
| CVE-2021-20407 | HIGH | 7.5 | 0.7% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used ... |
| CVE-2021-20406 | MEDIUM | 4.9 | 0.5% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allo... |
| CVE-2021-27197 | HIGH | 8.1 | 0.8% | Feb 12, 2021 | DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextF... |
| CVE-2021-27205 | MEDIUM | 5.5 | 0.3% | Feb 12, 2021 | Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leadin... |
| CVE-2021-27204 | MEDIUM | 5.5 | 0.3% | Feb 12, 2021 | Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure. |
| CVE-2021-27188 | HIGH | 7.5 | 1.8% | Feb 12, 2021 | The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (acces... |
| CVE-2021-27187 | HIGH | 7.5 | 2.0% | Feb 12, 2021 | The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in lo... |
| CVE-2021-20651 | CRITICAL | 9.1 | 1.9% | Feb 12, 2021 | Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary fil... |
| CVE-2021-20650 | MEDIUM | 6.5 | 0.5% | Feb 12, 2021 | Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authenti... |
| CVE-2021-20649 | MEDIUM | 4.8 | 0.3% | Feb 12, 2021 | ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attac... |
| CVE-2021-20648 | MEDIUM | 6.8 | 0.4% | Feb 12, 2021 | ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vecto... |
| CVE-2021-20647 | MEDIUM | 6.5 | 0.5% | Feb 12, 2021 | Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentica... |
| CVE-2021-20646 | MEDIUM | 6.5 | 0.5% | Feb 12, 2021 | Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentica... |
| CVE-2021-20645 | MEDIUM | 5.4 | 0.7% | Feb 12, 2021 | Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary scr... |
| CVE-2021-20644 | MEDIUM | 6.1 | 0.6% | Feb 12, 2021 | ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafte... |
| CVE-2021-20643 | HIGH | 7.5 | 1.1% | Feb 12, 2021 | Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password o... |
| CVE-2021-20642 | MEDIUM | 6.5 | 1.0% | Feb 12, 2021 | Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-... |
| CVE-2021-20641 | MEDIUM | 6.5 | 0.5% | Feb 12, 2021 | Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentica... |
| CVE-2021-20640 | MEDIUM | 6.8 | 0.5% | Feb 12, 2021 | Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an a... |
| CVE-2021-20639 | MEDIUM | 6.8 | 0.4% | Feb 12, 2021 | LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified... |
| CVE-2021-20638 | MEDIUM | 6.8 | 0.4% | Feb 12, 2021 | LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified... |
| CVE-2021-20637 | MEDIUM | 6.5 | 1.0% | Feb 12, 2021 | Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denia... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now