2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25912 | CRITICAL | 9.8 | 3.3% | Feb 2, 2021 | Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service ... |
| CVE-2021-3378 | CRITICAL | 9.8 | 97.5% | Feb 1, 2021 | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl... |
| CVE-2021-23330 | CRITICAL | 9.8 | 5.2% | Feb 1, 2021 | All versions of package launchpad are vulnerable to Command Injection via stop. |
| CVE-2021-21276 | CRITICAL | 9.3 | 7.2% | Feb 1, 2021 | Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attacker... |
| CVE-2021-3346 | CRITICAL | 9.8 | 1.6% | Jan 29, 2021 | Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template. |
| CVE-2021-26305 | CRITICAL | 9.8 | 1.7% | Jan 29, 2021 | An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implement... |
| CVE-2021-3160 | CRITICAL | 9.8 | 4.7% | Jan 28, 2021 | Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product ... |
| CVE-2021-3331 | CRITICAL | 9.8 | 7.4% | Jan 27, 2021 | WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted UR... |
| CVE-2021-3325 | CRITICAL | 9.8 | 2.2% | Jan 27, 2021 | Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation... |
| CVE-2021-25311 | CRITICAL | 9.9 | 3.2% | Jan 27, 2021 | condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, ... |
| CVE-2021-21278 | CRITICAL | 9.8 | 1.6% | Jan 26, 2021 | RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic... |
| CVE-2021-3304 | CRITICAL | 9.8 | 1.3% | Jan 26, 2021 | Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI. |
| CVE-2021-3286 | CRITICAL | 9.8 | 1.0% | Jan 26, 2021 | SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variati... |
| CVE-2021-3278 | CRITICAL | 9.8 | 25.3% | Jan 26, 2021 | Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection ... |
| CVE-2021-3199 | CRITICAL | 9.8 | 8.2% | Jan 26, 2021 | Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT... |
| CVE-2021-3193 | CRITICAL | 9.8 | 9.8% | Jan 26, 2021 | Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7... |
| CVE-2021-3190 | CRITICAL | 9.8 | 5.3% | Jan 26, 2021 | The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by... |
| CVE-2021-3188 | CRITICAL | 9.8 | 1.8% | Jan 26, 2021 | phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports. |
| CVE-2021-3185 | CRITICAL | 9.8 | 2.4% | Jan 26, 2021 | A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an ... |
| CVE-2021-25907 | CRITICAL | 9.8 | 1.6% | Jan 26, 2021 | An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} do... |
| CVE-2021-25905 | CRITICAL | 9.1 | 1.6% | Jan 26, 2021 | An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized mem... |
| CVE-2021-25900 | CRITICAL | 9.8 | 1.7% | Jan 26, 2021 | An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer ... |
| CVE-2021-23901 | CRITICAL | 9.1 | 4.4% | Jan 25, 2021 | An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch... |
| CVE-2021-1225 | CRITICAL | 9.1 | 1.4% | Jan 20, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthent... |
| CVE-2021-1142 | CRITICAL | 9.8 | 4.3% | Jan 20, 2021 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now