2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-20658CRITICAL9.8SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server ...
CVE-2021-27582CRITICAL9.1org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect th...
CVE-2021-21155CRITICAL9.6Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had c...
CVE-2021-21154CRITICAL9.6Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised ...
CVE-2021-21151CRITICAL9.6Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sa...
CVE-2021-21150CRITICAL9.6Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had comprom...
CVE-2021-27228CRITICAL9.8An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are...
CVE-2021-3120CRITICAL9.8An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allo...
CVE-2021-26120CRITICAL9.8Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
CVE-2021-24115CRITICAL9.8In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, ba...
CVE-2021-27514CRITICAL9.8EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-f...
CVE-2021-20588CRITICAL9.8Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Mo...
CVE-2021-20587CRITICAL9.8Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuratio...
CVE-2021-3210CRITICAL9.6components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrar...
CVE-2021-26747CRITICAL9.8Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading t...
CVE-2021-27335CRITICAL9.8KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoseria...
CVE-2021-27329CRITICAL10Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names.
CVE-2021-27378CRITICAL9.8An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle ...
CVE-2021-27377CRITICAL9.8An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_n...
CVE-2021-27376CRITICAL9.8An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain ver...
CVE-2021-27362CRITICAL9.8The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0...
CVE-2021-26809CRITICAL9.8PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
CVE-2021-25779CRITICAL9.8Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page.
CVE-2021-22855CRITICAL9.8The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can sen...
CVE-2021-27104CRITICAL9.8Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now