2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26637 | CRITICAL | 9.8 | 1.7% | Jun 23, 2022 | There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-... |
| CVE-2021-26636 | CRITICAL | 9.6 | 1.4% | Jun 23, 2022 | Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to in... |
| CVE-2021-40903 | CRITICAL | 9.8 | 4.4% | Jun 17, 2022 | A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flas... |
| CVE-2021-45024 | CRITICAL | 9.8 | 1.3% | Jun 17, 2022 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to X... |
| CVE-2021-41408 | CRITICAL | 9.8 | 1.1% | Jun 17, 2022 | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. |
| CVE-2021-41487 | CRITICAL | 9.8 | 1.6% | Jun 16, 2022 | NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'. |
| CVE-2021-41654 | CRITICAL | 9.8 | 1.0% | Jun 16, 2022 | SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the ... |
| CVE-2021-41411 | CRITICAL | 9.8 | 1.2% | Jun 16, 2022 | drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator cla... |
| CVE-2021-41403 | CRITICAL | 9.8 | 17.2% | Jun 15, 2022 | flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. |
| CVE-2021-41418 | CRITICAL | 9.8 | 0.9% | Jun 15, 2022 | AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' acces... |
| CVE-2021-40940 | CRITICAL | 9.8 | 1.6% | Jun 15, 2022 | Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability. |
| CVE-2021-40212 | CRITICAL | 9.8 | 1.9% | Jun 15, 2022 | An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, informa... |
| CVE-2021-42675 | CRITICAL | 9.8 | 3.1% | Jun 14, 2022 | Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP fi... |
| CVE-2021-35104 | CRITICAL | 9.8 | 0.7% | Jun 14, 2022 | Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdr... |
| CVE-2021-35083 | CRITICAL | 9.1 | 0.5% | Jun 14, 2022 | Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon... |
| CVE-2021-35081 | CRITICAL | 9.8 | 0.7% | Jun 14, 2022 | Possible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS... |
| CVE-2021-30341 | CRITICAL | 9.8 | 0.7% | Jun 14, 2022 | Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Comp... |
| CVE-2021-41662 | CRITICAL | 9.8 | 2.0% | Jun 13, 2022 | The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a mal... |
| CVE-2021-41661 | CRITICAL | 9.8 | 1.2% | Jun 13, 2022 | Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP fil... |
| CVE-2021-40604 | CRITICAL | 9.1 | 1.1% | Jun 13, 2022 | A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users... |
| CVE-2021-40036 | CRITICAL | 9.8 | 0.9% | Jun 13, 2022 | The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in m... |
| CVE-2021-37404 | CRITICAL | 9.8 | 2.9% | Jun 13, 2022 | There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user wit... |
| CVE-2021-41749 | CRITICAL | 9.8 | 17.2% | Jun 12, 2022 | In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Si... |
| CVE-2021-41756 | CRITICAL | 9.8 | 1.2% | Jun 10, 2022 | dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php. |
| CVE-2021-41755 | CRITICAL | 9.8 | 1.2% | Jun 10, 2022 | dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now