2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-23128CRITICAL9.1An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (...
CVE-2021-23127CRITICAL9.1An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to ...
CVE-2021-23344CRITICAL9.8The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
CVE-2021-27931CRITICAL9.1LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControl...
CVE-2021-22681CRITICAL9.8Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key ...
CVE-2021-21978CRITICAL9.8VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val...
CVE-2021-27215CRITICAL9.8An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. ...
CVE-2021-21353CRITICAL9Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker wa...
CVE-2021-21352CRITICAL9.1Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In TimeTracker before version ...
CVE-2021-27078CRITICAL9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26855CRITICAL9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26412CRITICAL9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-21513CRITICAL9.8Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server ...
CVE-2021-21322CRITICAL9.8fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with h...
CVE-2021-21321CRITICAL10fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In...
CVE-2021-27730CRITICAL9.8Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. Th...
CVE-2021-27804CRITICAL9.8JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.
CVE-2021-25309CRITICAL9.8The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout...
CVE-2021-27886CRITICAL9.8rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metachara...
CVE-2021-3342CRITICAL9.8EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a...
CVE-2021-27877CRITICAL9.8An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat...
CVE-2021-26703CRITICAL9.8EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input t...
CVE-2021-26476CRITICAL9.8EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
CVE-2021-25914CRITICAL9.8Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of...
CVE-2021-25833CRITICAL9.8A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now