2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-26637CRITICAL9.8There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-...
CVE-2021-26636CRITICAL9.6Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to in...
CVE-2021-40903CRITICAL9.8A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flas...
CVE-2021-45024CRITICAL9.8ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to X...
CVE-2021-41408CRITICAL9.8VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
CVE-2021-41487CRITICAL9.8NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
CVE-2021-41654CRITICAL9.8SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the ...
CVE-2021-41411CRITICAL9.8drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator cla...
CVE-2021-41403CRITICAL9.8flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
CVE-2021-41418CRITICAL9.8AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' acces...
CVE-2021-40940CRITICAL9.8Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
CVE-2021-40212CRITICAL9.8An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, informa...
CVE-2021-42675CRITICAL9.8Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP fi...
CVE-2021-35104CRITICAL9.8Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdr...
CVE-2021-35083CRITICAL9.1Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon...
CVE-2021-35081CRITICAL9.8Possible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS...
CVE-2021-30341CRITICAL9.8Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Comp...
CVE-2021-41662CRITICAL9.8The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a mal...
CVE-2021-41661CRITICAL9.8Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP fil...
CVE-2021-40604CRITICAL9.1A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users...
CVE-2021-40036CRITICAL9.8The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in m...
CVE-2021-37404CRITICAL9.8There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user wit...
CVE-2021-41749CRITICAL9.8In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Si...
CVE-2021-41756CRITICAL9.8dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.
CVE-2021-41755CRITICAL9.8dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now