2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-22648CRITICAL9.8Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
CVE-2021-22646CRITICAL9.8The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TB...
CVE-2021-22644CRITICAL9.8Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
CVE-2021-22640CRITICAL9.8An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
CVE-2021-23451CRITICAL9.8The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-ti...
CVE-2021-23397CRITICAL9.8All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer...
CVE-2021-23373CRITICAL9.8All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.
CVE-2021-41419CRITICAL9.8QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
CVE-2021-40874CRITICAL9.8An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST ...
CVE-2021-36711CRITICAL9.8WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
CVE-2021-44222CRITICAL9.1A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service o...
CVE-2021-35283CRITICAL9.8SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via...
CVE-2021-29281CRITICAL9.8File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik ...
CVE-2021-46825CRITICAL9.1Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauth...
CVE-2021-43702CRITICAL9ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitiz...
CVE-2021-32428CRITICAL9.8SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books...
CVE-2021-37778CRITICAL9.8There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code ...
CVE-2021-41506CRITICAL9.8Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI351...
CVE-2021-40663CRITICAL9.8deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes...
CVE-2021-40643CRITICAL9.8EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the...
CVE-2021-40597CRITICAL9.8The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.
CVE-2021-39409CRITICAL9.8A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without n...
CVE-2021-38945CRITICAL9.8IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by impro...
CVE-2021-40954CRITICAL9.8Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary cod...
CVE-2021-26638CRITICAL9.8Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and inform...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now