2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20410MEDIUM5.3IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an...
CVE-2021-20409HIGH7.5IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, cau...
CVE-2021-20408MEDIUM5.5IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to...
CVE-2021-20407HIGH7.5IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used ...
CVE-2021-20406MEDIUM4.9IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allo...
CVE-2021-27197HIGH8.1DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextF...
CVE-2021-27205MEDIUM5.5Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leadin...
CVE-2021-27204MEDIUM5.5Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
CVE-2021-27188HIGH7.5The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (acces...
CVE-2021-27187HIGH7.5The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in lo...
CVE-2021-20651CRITICAL9.1Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary fil...
CVE-2021-20650MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authenti...
CVE-2021-20649MEDIUM4.8ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attac...
CVE-2021-20648MEDIUM6.8ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vecto...
CVE-2021-20647MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentica...
CVE-2021-20646MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentica...
CVE-2021-20645MEDIUM5.4Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary scr...
CVE-2021-20644MEDIUM6.1ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafte...
CVE-2021-20643HIGH7.5Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password o...
CVE-2021-20642MEDIUM6.5Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-...
CVE-2021-20641MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentica...
CVE-2021-20640MEDIUM6.8Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an a...
CVE-2021-20639MEDIUM6.8LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified...
CVE-2021-20638MEDIUM6.8LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified...
CVE-2021-20637MEDIUM6.5Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denia...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now