2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29071 | CRITICAL | 9 | 0.7% | Mar 23, 2021 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12... |
| CVE-2021-29067 | CRITICAL | 9.6 | 0.6% | Mar 23, 2021 | Certain NETGEAR devices are affected by authentication bypass. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4,... |
| CVE-2021-29066 | CRITICAL | 9.6 | 0.6% | Mar 23, 2021 | Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.1... |
| CVE-2021-29065 | CRITICAL | 9.6 | 0.6% | Mar 23, 2021 | NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass. |
| CVE-2021-21351 | CRITICAL | 9.1 | 82.6% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21350 | CRITICAL | 9.8 | 15.6% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21347 | CRITICAL | 9.8 | 14.7% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21346 | CRITICAL | 9.8 | 76.9% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21345 | CRITICAL | 9.9 | 73.0% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21344 | CRITICAL | 9.8 | 76.5% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-21342 | CRITICAL | 9.1 | 50.1% | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne... |
| CVE-2021-26295 | CRITICAL | 9.8 | 98.0% | Mar 22, 2021 | Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to suc... |
| CVE-2021-28955 | CRITICAL | 9.8 | 1.5% | Mar 22, 2021 | git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in cert... |
| CVE-2021-26990 | CRITICAL | 9.1 | 1.5% | Mar 19, 2021 | Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite... |
| CVE-2021-28834 | CRITICAL | 9.8 | 2.8% | Mar 19, 2021 | Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes ... |
| CVE-2021-25289 | CRITICAL | 9.8 | 2.3% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr ... |
| CVE-2021-26275 | CRITICAL | 9.8 | 3.0% | Mar 19, 2021 | The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function... |
| CVE-2021-28794 | CRITICAL | 9.8 | 2.1% | Mar 18, 2021 | The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath. |
| CVE-2021-24148 | CRITICAL | 9.8 | 3.4% | Mar 18, 2021 | A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign... |
| CVE-2021-24139 | CRITICAL | 9.8 | 5.4% | Mar 18, 2021 | Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL inje... |
| CVE-2021-22848 | CRITICAL | 9.8 | 1.0% | Mar 18, 2021 | HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL pa... |
| CVE-2021-22860 | CRITICAL | 9.8 | 2.6% | Mar 17, 2021 | EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vul... |
| CVE-2021-22859 | CRITICAL | 9.8 | 3.8% | Mar 17, 2021 | The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remo... |
| CVE-2021-28381 | CRITICAL | 9.8 | 1.0% | Mar 16, 2021 | The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper. |
| CVE-2021-28294 | CRITICAL | 9.8 | 3.7% | Mar 16, 2021 | Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now