LiveActive security incident?Get immediate response
CVE archive

January 2021

Browse CVE records published in January 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2235 matching CVEs · Page 4 of 45.

High · CVSS 8.5

CVE-2021-47880: Realtek Wireless LAN Utility 700.1631 - 'Realtek11nSU' Unquoted Service Path

Realtek Wireless LAN Utility 700.1631 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path by inserting malicious code in the system root path that would execute during application startup or system reboot.

Published Jan 21, 2026 · Updated Jan 22, 2026

High · CVSS 8.5

CVE-2021-47886: Pingzapper 2.3.1 - 'PingzapperSvc' Unquoted Service Path

Pingzapper 2.3.1 contains an unquoted service path vulnerability in the PingzapperSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Pingzapper\PZService.exe' to inject malicious executables and escalate privileges.

Published Jan 21, 2026 · Updated Jan 22, 2026

High · CVSS 8.5

CVE-2021-47887: Print Job Accounting 4.4.10 - 'OkiJaSvc' Unquoted Service Path

OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability in the OkiJaSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Print Job Accounting\' to inject malicious executables and escalate privileges.

Published Jan 21, 2026 · Updated Jan 22, 2026

High · CVSS 8.7

CVE-2021-47849: Mini Mouse 9.3.0 - Local File inclusion / Path Traversal

Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information endpoint. Attackers can retrieve file lists from system directories like /usr, /etc, and /var by manipulating file path parameters in API requests.

Published Jan 21, 2026 · Updated Jan 22, 2026

High · CVSS 8.7

CVE-2021-47850: Mini Mouse 9.2.0 - Path Traversal

Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted HTTP requests. Attackers can retrieve sensitive files like win.ini and list contents of system directories such as C:\Users\Public by manipulating file and path parameters.

Published Jan 21, 2026 · Updated Jan 22, 2026

Critical · CVSS 9.8

CVE-2021-47851: Mini Mouse 9.2.0 - Remote Code Execution

Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP endpoint. Attackers can leverage the /op=command endpoint to download and execute payloads by sending crafted JSON requests with malicious script commands.

Published Jan 21, 2026 · Updated Jan 22, 2026

High · CVSS 8.8

CVE-2021-47852: Rockstar Service - Insecure File Permissions

Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access.

Published Jan 21, 2026 · Updated Jan 22, 2026

High · CVSS 7.5

CVE-2021-47827: WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service

WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash the application by pasting malformed input. Attackers can trigger the vulnerability by copying a 300-character buffer of repeated 'A' characters into the mashREPL input field, causing the application to crash.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47826: Acer Backup Manager Module 3.0.0.99 - 'IScheduleSvc.exe' Unquoted Service Path

Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with elevated LocalSystem privileges.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47825: Acer Updater Service 1.2.3500.0 - 'UpdaterService.exe' Unquoted Service Path

Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during service startup.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 7.5

CVE-2021-47824: iDailyDiary 4.30 - Denial of Service (PoC)

iDailyDiary 4.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the preferences tab name field. Attackers can paste a 2,000,000 character buffer into the default diary tab name to trigger an application crash.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47828: BOOTP Turbo 2.0.0.1253 - 'bootpt.exe' Unquoted Service Path

BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to execute arbitrary code with elevated LocalSystem privileges during system startup or reboot.

Published Jan 16, 2026 · Updated Jan 16, 2026

Critical · CVSS 9.8

CVE-2021-47785: Ether_MP3_CD_Burner 1.3.8 - Buffer Overflow (SEH)

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can craft a malicious payload to overwrite SEH handlers and execute a bind shell on port 3110 by exploiting improper input validation.

Published Jan 15, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47790: Active WebCam 11.5 - Unquoted Service Path

Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables in specific directory locations to gain administrative access.

Published Jan 15, 2026 · Updated Jan 16, 2026

High · CVSS 7.5

CVE-2021-47791: SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Service

SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can trigger crashes by entering malformed paths, using invalid IP addresses, or clearing connection history in the client's interface.

Published Jan 15, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47792: Remote Mouse 4.002 - Unquoted Service Path

Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the RemoteMouseService to inject malicious executables and gain administrative access.

Published Jan 15, 2026 · Updated Jan 16, 2026

Medium · CVSS 5.3

CVE-2021-47820: Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 7.5

CVE-2021-47821: RarmaRadio 2.72.8 - Denial of Service

RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffers. Attackers can generate a 100,000 character buffer and paste it into multiple network settings fields to trigger application instability and potential crash.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47822: DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path

DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path locations to gain system-level access during service startup.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47823: ePowerSvc 6.0.3008.0 - 'ePowerSvc.exe' Unquoted Service Path

Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47829: DHCP Broadband 4.1.0.1503 - 'dhcpt.exe' Unquoted Service Path

DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files\DHCP Broadband 4\dhcpt.exe' to inject malicious code that will execute during service startup with LocalSystem permissions.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47833: WifiHotSpot 1.0.0.0 - 'WifiHotSpotService.exe' Unquoted Service Path

WifiHotSpot 1.0.0.0 contains an unquoted service path vulnerability in its WifiHotSpotService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 7.2

CVE-2021-47835: Freeter 1.2.1 - Persistent Cross-Site Scripting

Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads in custom widget titles and files. Attackers can craft malicious files with embedded scripts that execute when victims interact with the application, potentially enabling remote code execution.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 7.2

CVE-2021-47838: Markright 1.0 - Persistent Cross-Site Scripting

Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads in markdown files. Attackers can upload specially crafted markdown files that execute arbitrary JavaScript when opened, potentially enabling remote code execution on the victim's system.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 7.2

CVE-2021-47840: Moeditor 0.2.0 - Persistent Cross-Site Scripting

Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload specially crafted markdown files with embedded JavaScript that execute when opened, potentially enabling remote code execution on the victim's system.

Published Jan 16, 2026 · Updated Jan 16, 2026

Medium · CVSS 6.1

CVE-2021-47841: SnipCommand 0.1.0 - Persistent Cross-Site Scripting

SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into command snippets. Attackers can execute arbitrary code by embedding malicious JavaScript that triggers remote command execution through file or title inputs.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 7.2

CVE-2021-47842: StudyMD 0.3.2 - Persistent Cross-Site Scripting

StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47845: Spy Emergency 25.0.650 - Unquoted Service Path

Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergencyHealth.exe and SpyEmergencySrv.exe to inject malicious code during system startup or service restart.

Published Jan 16, 2026 · Updated Jan 16, 2026

High · CVSS 7.5

CVE-2021-47797: Leawo Prof. Media 11.0.0.1 - Denial of Service (DoS) (PoC)

Leawo Prof. Media 11.0.0.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized payload in the activation keycode field. Attackers can generate a 6000-byte buffer of repeated characters to trigger an application crash when pasted into the registration interface.

Published Jan 15, 2026 · Updated Jan 16, 2026

Critical · CVSS 9.8

CVE-2021-47798: NoteBurner 2.35 - Denial Of Service (DoS) (PoC)

NoteBurner 2.35 contains a buffer overflow vulnerability in the license code input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the 'Name' and 'Code' fields to trigger an application crash.

Published Jan 15, 2026 · Updated Jan 16, 2026

High · CVSS 8.8

CVE-2021-47801: Vianeos OctoPUS 5 - 'login_user' SQLi

Vianeos OctoPUS 5 contains a time-based blind SQL injection vulnerability in the 'login_user' parameter during authentication requests. Attackers can exploit this vulnerability by crafting malicious POST requests with specially constructed SQL payloads that trigger database sleep functions to extract information.

Published Jan 15, 2026 · Updated Jan 16, 2026

High · CVSS 8.5

CVE-2021-47803: iFunbox 4.2 - 'Apple Mobile Device Service' Unquoted Service Path

iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.

Published Jan 15, 2026 · Updated Jan 16, 2026

High · CVSS 7.5

CVE-2021-47813: Backup Key Recovery 2.2.7 - Denial of Service (PoC)

Backup Key Recovery 2.2.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a large buffer of 256 repeated characters into the registration key field to trigger application instability and potential crash.

Published Jan 15, 2026 · Updated Jan 16, 2026

Medium · CVSS 6.1

CVE-2021-47768: ImportExportTools NG 10.0.4 - HTML Injection

ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows remote attackers to inject malicious HTML payloads. Attackers can send emails with crafted HTML in the subject that execute during HTML export, potentially compromising user data or session credentials.

Published Jan 15, 2026 · Updated Jan 15, 2026

High · CVSS 8.5

CVE-2021-47773: Dynojet Power Core 2.3.0 - Unquoted Service Path

Dynojet Power Core 2.3.0 contains an unquoted service path vulnerability in the DJ.UpdateService that allows local authenticated users to potentially execute code with elevated privileges. Attackers can exploit the unquoted binary path by placing malicious executables in the service's file path to gain Local System access.

Published Jan 15, 2026 · Updated Jan 15, 2026

Medium · CVSS 6.8

CVE-2021-47759: MTPutty 1.0.1.21 - SSH Password Disclosure

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windows PowerShell process listing. Attackers can run a PowerShell command to retrieve the full command line of MTPutty processes, exposing plaintext SSH credentials.

Published Jan 15, 2026 · Updated Jan 15, 2026

High · CVSS 8.5

CVE-2021-47761: MilleGPG5 5.7.2 Luglio 2021 (x64) - Local Privilege Escalation

MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB bin directory. Attackers can replace the mysqld.exe with a malicious executable, which will execute with system privileges when the computer restarts.

Published Jan 15, 2026 · Updated Jan 15, 2026

High · CVSS 7.1

CVE-2021-47766: Kmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated)

Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that allows attackers to manipulate database queries. Attackers can exploit this vulnerability using boolean-based, error-based, and time-based blind SQL injection techniques to potentially extract or manipulate database information.

Published Jan 15, 2026 · Updated Jan 15, 2026

Critical · CVSS 9.8

CVE-2021-47774: Kingdia CD Extractor 3.0.2 - Buffer Overflow (SEH)

Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload exceeding 256 bytes to overwrite Structured Exception Handler and gain remote code execution through a bind shell.

Published Jan 15, 2026 · Updated Jan 15, 2026

High · CVSS 8.4

CVE-2021-47775: YouTube Video Grabber 1.9.9.1 - Buffer Overflow (SEH)

YouTube Video Grabber, now referred to as YouTube Downloader, 1.9.9.1 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious payload of 712 bytes with SEH manipulation to trigger a bind shell connection on a specified local port.

Published Jan 15, 2026 · Updated Jan 15, 2026

Critical · CVSS 9.8

CVE-2021-47781: Cmder Console Emulator 1.3.18 - 'Cmder.exe' Denial of Service (PoC)

Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a maliciously crafted .cmd file. Attackers can create a specially constructed .cmd file with repeated characters to overwhelm the console emulator's buffer and crash the application.

Published Jan 15, 2026 · Updated Jan 15, 2026

High · CVSS 7.5

CVE-2021-47784: Cyberfox Web Browser 52.9.1 - Denial of Service (PoC)

Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar with excessive data. Attackers can generate a 9,000,000 byte payload and paste it into the search bar to trigger an application crash.

Published Jan 15, 2026 · Updated Jan 15, 2026

Medium · CVSS 6.1

CVE-2021-24870: WP Fastest Cache < 0.9.5 - CSRF to Stored Cross-Site Scripting

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload

Published Jan 16, 2024 · Updated Jan 9, 2026

High · CVSS 7.5

CVE-2021-32837: mechanize vulnerable to ReDoS

mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to version 0.4.6. If a web server responds in a malicious way, then mechanize could crash. Version 0.4.6 has a patch for the issue.

Published Jan 17, 2023 · Updated Dec 22, 2025

Critical · CVSS 9.8

CVE-2021-3177: Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remo...

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

Published Jan 19, 2021 · Updated Dec 18, 2025

Unknown · CVSS Not scored

CVE-2021-45971: An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05....

An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (CommBufferData).

Published Jan 5, 2022 · Updated Nov 4, 2025

Unknown · CVSS Not scored

CVE-2021-45970: An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26....

An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the status code saved at the CommBuffer+4 location).

Published Jan 5, 2022 · Updated Nov 4, 2025

Unknown · CVSS Not scored

CVE-2021-45969: An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26...

An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the CommBuffer+8 location).

Published Jan 5, 2022 · Updated Nov 4, 2025