2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25913 | CRITICAL | 9.8 | 4.2% | Feb 8, 2021 | Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of s... |
| CVE-2021-22502 | CRITICAL | 9.8 | 96.7% | Feb 8, 2021 | Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The... |
| CVE-2021-26530 | CRITICAL | 9.1 | 1.5% | Feb 8, 2021 | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OO... |
| CVE-2021-26529 | CRITICAL | 9.1 | 1.5% | Feb 8, 2021 | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable... |
| CVE-2021-26528 | CRITICAL | 9.1 | 1.5% | Feb 8, 2021 | The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connect... |
| CVE-2021-21304 | CRITICAL | 9.8 | 1.9% | Feb 8, 2021 | Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.... |
| CVE-2021-26541 | CRITICAL | 9.8 | 5.4% | Feb 8, 2021 | The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability. |
| CVE-2021-26754 | CRITICAL | 9.8 | 4.6% | Feb 8, 2021 | wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order... |
| CVE-2021-3122 | CRITICAL | 9.8 | 87.4% | Feb 7, 2021 | CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (wit... |
| CVE-2021-3311 | CRITICAL | 9.8 | 2.9% | Feb 5, 2021 | An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a l... |
| CVE-2021-20623 | CRITICAL | 9.8 | 2.8% | Feb 5, 2021 | Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privileg... |
| CVE-2021-1295 | CRITICAL | 9.8 | 4.2% | Feb 4, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and... |
| CVE-2021-1294 | CRITICAL | 9.8 | 4.2% | Feb 4, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and... |
| CVE-2021-1293 | CRITICAL | 9.8 | 5.4% | Feb 4, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and... |
| CVE-2021-1292 | CRITICAL | 9.8 | 4.2% | Feb 4, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and... |
| CVE-2021-1291 | CRITICAL | 9.8 | 4.2% | Feb 4, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and... |
| CVE-2021-1290 | CRITICAL | 9.8 | 4.2% | Feb 4, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and... |
| CVE-2021-1289 | CRITICAL | 9.8 | 4.2% | Feb 4, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and... |
| CVE-2021-26689 | CRITICAL | 9.8 | 0.5% | Feb 4, 2021 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a us... |
| CVE-2021-26688 | CRITICAL | 9.8 | 0.4% | Feb 4, 2021 | An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security pr... |
| CVE-2021-26687 | CRITICAL | 9.8 | 0.5% | Feb 4, 2021 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, ... |
| CVE-2021-20016 | CRITICAL | 9.8 | 37.0% | Feb 4, 2021 | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform... |
| CVE-2021-3401 | CRITICAL | 9.8 | 10.5% | Feb 4, 2021 | Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely pass... |
| CVE-2021-25274 | CRITICAL | 9.8 | 36.4% | Feb 3, 2021 | The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set p... |
| CVE-2021-25770 | CRITICAL | 9.8 | 3.5% | Feb 3, 2021 | In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code e... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now