2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-20617CRITICAL9.8Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows ...
CVE-2021-3028CRITICAL9.8git-big-picture before 1.0.0 mishandles ' characters in a branch name, leading to code execution.
CVE-2021-23899CRITICAL9.8OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allo...
CVE-2021-3129CRITICAL9.8Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra...
CVE-2021-21465CRITICAL9.9The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the b...
CVE-2021-0316CRITICAL9.8In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This ...
CVE-2021-3118CRITICAL9.8EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the passwo...
CVE-2021-21115CRITICAL9.6User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised t...
CVE-2021-21111CRITICAL9.6Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a use...
CVE-2021-21110CRITICAL9.6Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform...
CVE-2021-21109CRITICAL9.6Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the ren...
CVE-2021-21108CRITICAL9.6Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the render...
CVE-2021-21107CRITICAL9.6Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compr...
CVE-2021-21106CRITICAL9.6Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the ren...
CVE-2021-3029CRITICAL9.8EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters...
CVE-2021-3021CRITICAL9.8ISPConfig before 3.2.2 allows SQL injection.
CVE-2021-3018CRITICAL9.8ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the ...
CVE-2021-3007CRITICAL9.8Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now