2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-25912CRITICAL9.8Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service ...
CVE-2021-3378CRITICAL9.8FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl...
CVE-2021-23330CRITICAL9.8All versions of package launchpad are vulnerable to Command Injection via stop.
CVE-2021-21276CRITICAL9.3Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attacker...
CVE-2021-3346CRITICAL9.8Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.
CVE-2021-26305CRITICAL9.8An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implement...
CVE-2021-3160CRITICAL9.8Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product ...
CVE-2021-3331CRITICAL9.8WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted UR...
CVE-2021-3325CRITICAL9.8Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation...
CVE-2021-25311CRITICAL9.9condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, ...
CVE-2021-21278CRITICAL9.8RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic...
CVE-2021-3304CRITICAL9.8Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.
CVE-2021-3286CRITICAL9.8SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variati...
CVE-2021-3278CRITICAL9.8Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection ...
CVE-2021-3199CRITICAL9.8Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
CVE-2021-3193CRITICAL9.8Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7...
CVE-2021-3190CRITICAL9.8The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by...
CVE-2021-3188CRITICAL9.8phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
CVE-2021-3185CRITICAL9.8A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an ...
CVE-2021-25907CRITICAL9.8An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} do...
CVE-2021-25905CRITICAL9.1An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized mem...
CVE-2021-25900CRITICAL9.8An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer ...
CVE-2021-23901CRITICAL9.1An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch...
CVE-2021-1225CRITICAL9.1Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthent...
CVE-2021-1142CRITICAL9.8Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now