2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20658 | CRITICAL | 9.8 | 3.7% | Feb 24, 2021 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server ... |
| CVE-2021-27582 | CRITICAL | 9.1 | 2.2% | Feb 23, 2021 | org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect th... |
| CVE-2021-21155 | CRITICAL | 9.6 | 1.3% | Feb 22, 2021 | Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had c... |
| CVE-2021-21154 | CRITICAL | 9.6 | 1.4% | Feb 22, 2021 | Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised ... |
| CVE-2021-21151 | CRITICAL | 9.6 | 1.1% | Feb 22, 2021 | Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sa... |
| CVE-2021-21150 | CRITICAL | 9.6 | 1.2% | Feb 22, 2021 | Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had comprom... |
| CVE-2021-27228 | CRITICAL | 9.8 | 1.6% | Feb 22, 2021 | An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are... |
| CVE-2021-3120 | CRITICAL | 9.8 | 36.8% | Feb 22, 2021 | An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allo... |
| CVE-2021-26120 | CRITICAL | 9.8 | 82.3% | Feb 22, 2021 | Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. |
| CVE-2021-24115 | CRITICAL | 9.8 | 2.0% | Feb 22, 2021 | In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, ba... |
| CVE-2021-27514 | CRITICAL | 9.8 | 3.5% | Feb 22, 2021 | EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-f... |
| CVE-2021-20588 | CRITICAL | 9.8 | 5.9% | Feb 19, 2021 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Mo... |
| CVE-2021-20587 | CRITICAL | 9.8 | 3.7% | Feb 19, 2021 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuratio... |
| CVE-2021-3210 | CRITICAL | 9.6 | 2.7% | Feb 19, 2021 | components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrar... |
| CVE-2021-26747 | CRITICAL | 9.8 | 53.6% | Feb 18, 2021 | Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading t... |
| CVE-2021-27335 | CRITICAL | 9.8 | 3.0% | Feb 18, 2021 | KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoseria... |
| CVE-2021-27329 | CRITICAL | 10 | 1.5% | Feb 18, 2021 | Friendica 2021.01 allows SSRF via parse_url?binurl= for DNS lookups or HTTP requests to arbitrary domain names. |
| CVE-2021-27378 | CRITICAL | 9.8 | 1.2% | Feb 18, 2021 | An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle ... |
| CVE-2021-27377 | CRITICAL | 9.8 | 1.3% | Feb 18, 2021 | An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_n... |
| CVE-2021-27376 | CRITICAL | 9.8 | 1.4% | Feb 18, 2021 | An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain ver... |
| CVE-2021-27362 | CRITICAL | 9.8 | 4.5% | Feb 17, 2021 | The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0... |
| CVE-2021-26809 | CRITICAL | 9.8 | 2.1% | Feb 17, 2021 | PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php. |
| CVE-2021-25779 | CRITICAL | 9.8 | 1.1% | Feb 17, 2021 | Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page. |
| CVE-2021-22855 | CRITICAL | 9.8 | 2.0% | Feb 17, 2021 | The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can sen... |
| CVE-2021-27104 | CRITICAL | 9.8 | 56.7% | Feb 16, 2021 | Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now