2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-41265HIGH8.8Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentica...
CVE-2021-40282HIGH8.8An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary...
CVE-2021-40281HIGH8.8An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary use...
CVE-2021-39002HIGH7.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expec...
CVE-2021-38951HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia...
CVE-2021-29678HIGH8.7IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user wit...
CVE-2021-22568HIGH8.8When using the dart pub publish command to publish a package to a third-party package server, the request would be authe...
CVE-2021-20373HIGH7.5IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as un...
CVE-2021-41246HIGH8.8Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions...
CVE-2021-40280HIGH7.2An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.
CVE-2021-40279HIGH7.2An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.
CVE-2021-21955HIGH7.5An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary...
CVE-2021-20145HIGH7.5Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon ...
CVE-2021-20144HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server ser...
CVE-2021-20143HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server ser...
CVE-2021-20142HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server ser...
CVE-2021-20141HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server ser...
CVE-2021-20140HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server ser...
CVE-2021-20139HIGH8.8An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server serv...
CVE-2021-20138HIGH8.8An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web inter...
CVE-2021-41449HIGH7.1A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote ...
CVE-2021-43071HIGH8.8A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and b...
CVE-2021-43068HIGH8.1A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authen...
CVE-2021-43065HIGH7.8A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, ver...
CVE-2021-36194HIGH8.8Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now