2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20617 | CRITICAL | 9.8 | 7.9% | Jan 14, 2021 | Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows ... |
| CVE-2021-3028 | CRITICAL | 9.8 | 2.7% | Jan 13, 2021 | git-big-picture before 1.0.0 mishandles ' characters in a branch name, leading to code execution. |
| CVE-2021-23899 | CRITICAL | 9.8 | 2.1% | Jan 13, 2021 | OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allo... |
| CVE-2021-3129 | CRITICAL | 9.8 | 99.9% | Jan 12, 2021 | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra... |
| CVE-2021-21465 | CRITICAL | 9.9 | 3.7% | Jan 12, 2021 | The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the b... |
| CVE-2021-0316 | CRITICAL | 9.8 | 3.1% | Jan 11, 2021 | In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This ... |
| CVE-2021-3118 | CRITICAL | 9.8 | 1.8% | Jan 11, 2021 | EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the passwo... |
| CVE-2021-21115 | CRITICAL | 9.6 | 1.4% | Jan 8, 2021 | User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised t... |
| CVE-2021-21111 | CRITICAL | 9.6 | 1.1% | Jan 8, 2021 | Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a use... |
| CVE-2021-21110 | CRITICAL | 9.6 | 3.1% | Jan 8, 2021 | Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform... |
| CVE-2021-21109 | CRITICAL | 9.6 | 1.3% | Jan 8, 2021 | Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the ren... |
| CVE-2021-21108 | CRITICAL | 9.6 | 1.3% | Jan 8, 2021 | Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the render... |
| CVE-2021-21107 | CRITICAL | 9.6 | 1.1% | Jan 8, 2021 | Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compr... |
| CVE-2021-21106 | CRITICAL | 9.6 | 2.2% | Jan 8, 2021 | Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the ren... |
| CVE-2021-3029 | CRITICAL | 9.8 | 3.0% | Jan 7, 2021 | EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters... |
| CVE-2021-3021 | CRITICAL | 9.8 | 2.1% | Jan 5, 2021 | ISPConfig before 3.2.2 allows SQL injection. |
| CVE-2021-3018 | CRITICAL | 9.8 | 19.5% | Jan 5, 2021 | ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the ... |
| CVE-2021-3007 | CRITICAL | 9.8 | 75.3% | Jan 4, 2021 | Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now