LiveActive security incident?Get immediate response
CVE archive

2021 CVE Archive

Browse CVE records published in 2021 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 22591 matching CVEs · Page 14 of 452.

Unknown · CVSS Not scored

CVE-2021-36581: Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload.

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

Published Sep 14, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-36460: VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the h...

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

Published Apr 25, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-34204: D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials.

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same, and they cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.

Published Jun 16, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-34203: D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control.

D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password and port. An attacker can easily use telnet to log in, modify routing information, monitor the traffic of all devices under the router, hijack DNS and phishing attacks. In addition, this interface is likely to be questioned by customers as a backdoor, because the interface should not be exposed.

Published Jun 16, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-34202: There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04.

There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04. Ordinary permissions can be elevated to administrator permissions, resulting in local arbitrary code execution. An attacker can combine other vulnerabilities to further achieve the purpose of remote code execution.

Published Jun 16, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-34201: D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow.

D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, causing the process crashes or changes.

Published Jun 16, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-31659: TP-Link TL-SG2005, TL-SG2008, etc.

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A malicious link opened by the switch administrator may cause the password of the switch to be modified and the configuration file to be tampered with.

Published Jun 10, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-31658: TP-Link TL-SG2005, TL-SG2008, etc.

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device description" function only judges the length of the received data, and does not filter special characters. This vulnerability will cause the application to crash, and all device configuration information will be erased.

Published Jun 10, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-29051: Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1...

Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_XXXXXXXXXXXX_assetEntryId parameter.

Published May 17, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-29048: Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal...

Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fix pack 11 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_name parameter.

Published May 17, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-29046: Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Por...

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_categories_admin_web_portlet_AssetCategoriesAdminPortlet_title parameter.

Published May 17, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-29045: Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Lifera...

Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_redirect_web_internal_portlet_RedirectPortlet_destinationURL parameter.

Published May 17, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-29044: Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Li...

Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_my_sites_web_portlet_MySitesPortlet_comments parameter.

Published May 17, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-29043: The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1...

The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.

Published May 17, 2021 · Updated Jul 9, 2026