2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-29071CRITICAL9Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12...
CVE-2021-29067CRITICAL9.6Certain NETGEAR devices are affected by authentication bypass. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4,...
CVE-2021-29066CRITICAL9.6Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.1...
CVE-2021-29065CRITICAL9.6NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.
CVE-2021-21351CRITICAL9.1XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21350CRITICAL9.8XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21347CRITICAL9.8XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21346CRITICAL9.8XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21345CRITICAL9.9XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21344CRITICAL9.8XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21342CRITICAL9.1XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-26295CRITICAL9.8Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to suc...
CVE-2021-28955CRITICAL9.8git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in cert...
CVE-2021-26990CRITICAL9.1Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite...
CVE-2021-28834CRITICAL9.8Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes ...
CVE-2021-25289CRITICAL9.8An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr ...
CVE-2021-26275CRITICAL9.8The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function...
CVE-2021-28794CRITICAL9.8The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.
CVE-2021-24148CRITICAL9.8A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign...
CVE-2021-24139CRITICAL9.8Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL inje...
CVE-2021-22848CRITICAL9.8HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL pa...
CVE-2021-22860CRITICAL9.8EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vul...
CVE-2021-22859CRITICAL9.8The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remo...
CVE-2021-28381CRITICAL9.8The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper.
CVE-2021-28294CRITICAL9.8Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now