2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-46851CRITICAL9.8The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerabil...
CVE-2021-34569CRITICAL9.8In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to...
CVE-2021-34566CRITICAL9.1In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co...
CVE-2021-40241CRITICAL9.8xfig 3.2.7 is vulnerable to Buffer Overflow.
CVE-2021-42777CRITICAL9.8Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrar...
CVE-2021-38733CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
CVE-2021-38732CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
CVE-2021-38731CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
CVE-2021-38730CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
CVE-2021-38729CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
CVE-2021-38217CRITICAL9.8SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
CVE-2021-38737CRITICAL9.8SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
CVE-2021-38736CRITICAL9.8SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
CVE-2021-38734CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
CVE-2021-37782CRITICAL9.8Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
CVE-2021-38397CRITICAL10Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may all...
CVE-2021-38395CRITICAL9.8Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special eleme...
CVE-2021-46848CRITICAL9.1GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
CVE-2021-42010CRITICAL9.8Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Ple...
CVE-2021-26731CRITICAL9.8Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_rest...
CVE-2021-26730CRITICAL9.8A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allow...
CVE-2021-26729CRITICAL9.8Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_re...
CVE-2021-26728CRITICAL9.8Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice all...
CVE-2021-26727CRITICAL9.8Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_...
CVE-2021-42553CRITICAL9.8A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now