2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-25913CRITICAL9.8Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of s...
CVE-2021-22502CRITICAL9.8Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The...
CVE-2021-26530CRITICAL9.1The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OO...
CVE-2021-26529CRITICAL9.1The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable...
CVE-2021-26528CRITICAL9.1The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connect...
CVE-2021-21304CRITICAL9.8Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7....
CVE-2021-26541CRITICAL9.8The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.
CVE-2021-26754CRITICAL9.8wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order...
CVE-2021-3122CRITICAL9.8CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (wit...
CVE-2021-3311CRITICAL9.8An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a l...
CVE-2021-20623CRITICAL9.8Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privileg...
CVE-2021-1295CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and...
CVE-2021-1294CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and...
CVE-2021-1293CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and...
CVE-2021-1292CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and...
CVE-2021-1291CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and...
CVE-2021-1290CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and...
CVE-2021-1289CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and...
CVE-2021-26689CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a us...
CVE-2021-26688CRITICAL9.8An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security pr...
CVE-2021-26687CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, ...
CVE-2021-20016CRITICAL9.8A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform...
CVE-2021-3401CRITICAL9.8Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely pass...
CVE-2021-25274CRITICAL9.8The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set p...
CVE-2021-25770CRITICAL9.8In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code e...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now