2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27103 | CRITICAL | 9.8 | 11.4% | Feb 16, 2021 | Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed vers... |
| CVE-2021-27101 | CRITICAL | 9.8 | 6.0% | Feb 16, 2021 | Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.... |
| CVE-2021-25648 | CRITICAL | 9.8 | 1.2% | Feb 16, 2021 | Mobile application "Testes de Codigo" 11.4 and prior allows an attacker to gain access to the administrative interface a... |
| CVE-2021-27236 | CRITICAL | 9.8 | 2.1% | Feb 16, 2021 | An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion,... |
| CVE-2021-27234 | CRITICAL | 9.8 | 1.0% | Feb 16, 2021 | An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. The web application suffers from SQL injection on Adminl... |
| CVE-2021-3239 | CRITICAL | 9.8 | 17.9% | Feb 15, 2021 | E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to exec... |
| CVE-2021-26822 | CRITICAL | 9.8 | 4.8% | Feb 15, 2021 | Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in ... |
| CVE-2021-26201 | CRITICAL | 9.8 | 2.2% | Feb 15, 2021 | The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attack... |
| CVE-2021-26200 | CRITICAL | 9.8 | 2.2% | Feb 15, 2021 | The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login... |
| CVE-2021-3375 | CRITICAL | 9.8 | 3.5% | Feb 15, 2021 | ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or a... |
| CVE-2021-27213 | CRITICAL | 9.8 | 2.6% | Feb 14, 2021 | config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load ... |
| CVE-2021-26753 | CRITICAL | 9.9 | 1.1% | Feb 12, 2021 | NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php... |
| CVE-2021-22504 | CRITICAL | 9.8 | 3.3% | Feb 12, 2021 | Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x... |
| CVE-2021-20651 | CRITICAL | 9.1 | 1.9% | Feb 12, 2021 | Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary fil... |
| CVE-2021-21014 | CRITICAL | 9.1 | 4.2% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload res... |
| CVE-2021-21025 | CRITICAL | 9.1 | 3.3% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in ... |
| CVE-2021-21024 | CRITICAL | 9.1 | 2.8% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injecti... |
| CVE-2021-21019 | CRITICAL | 9.1 | 3.6% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in ... |
| CVE-2021-21018 | CRITICAL | 9.1 | 4.1% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command inject... |
| CVE-2021-21016 | CRITICAL | 9.1 | 4.7% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command inject... |
| CVE-2021-21307 | CRITICAL | 9.8 | 89.2% | Feb 11, 2021 | Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. ... |
| CVE-2021-25689 | CRITICAL | 9.8 | 1.5% | Feb 11, 2021 | An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remote... |
| CVE-2021-22658 | CRITICAL | 9.8 | 12.7% | Feb 11, 2021 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalat... |
| CVE-2021-22652 | CRITICAL | 9.8 | 36.8% | Feb 11, 2021 | Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a... |
| CVE-2021-27185 | CRITICAL | 9.8 | 4.8% | Feb 10, 2021 | The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now