2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41754 | CRITICAL | 9.8 | 1.2% | Jun 10, 2022 | dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php. |
| CVE-2021-27786 | CRITICAL | 9.8 | 0.5% | Jun 9, 2022 | Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This requ... |
| CVE-2021-40589 | CRITICAL | 9.8 | 1.1% | Jun 8, 2022 | ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fil... |
| CVE-2021-42890 | CRITICAL | 9.8 | 1.9% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file... |
| CVE-2021-42888 | CRITICAL | 9.8 | 1.9% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file ... |
| CVE-2021-42887 | CRITICAL | 9.8 | 42.9% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. |
| CVE-2021-42885 | CRITICAL | 9.8 | 2.5% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file gl... |
| CVE-2021-42884 | CRITICAL | 9.8 | 2.5% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file g... |
| CVE-2021-33473 | CRITICAL | 9.1 | 1.0% | Jun 2, 2022 | An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when... |
| CVE-2021-42875 | CRITICAL | 9.8 | 5.0% | Jun 2, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the ... |
| CVE-2021-45983 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution. |
| CVE-2021-45981 | CRITICAL | 9.8 | 1.0% | Jun 2, 2022 | NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. |
| CVE-2021-44098 | CRITICAL | 9.8 | 1.4% | Jun 2, 2022 | EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remot... |
| CVE-2021-44097 | CRITICAL | 9.8 | 1.4% | Jun 2, 2022 | EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This a... |
| CVE-2021-44096 | CRITICAL | 9.8 | 1.2% | Jun 2, 2022 | EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action... |
| CVE-2021-44095 | CRITICAL | 9.8 | 2.2% | Jun 2, 2022 | A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a ... |
| CVE-2021-42872 | CRITICAL | 9.8 | 8.2% | Jun 2, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code... |
| CVE-2021-34084 | CRITICAL | 9.8 | 3.0% | Jun 2, 2022 | OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to ex... |
| CVE-2021-34082 | CRITICAL | 9.8 | 4.9% | Jun 2, 2022 | OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7... |
| CVE-2021-34080 | CRITICAL | 9.8 | 3.2% | Jun 2, 2022 | OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands v... |
| CVE-2021-34079 | CRITICAL | 9.8 | 4.2% | Jun 2, 2022 | OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands ... |
| CVE-2021-26634 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and... |
| CVE-2021-26633 | CRITICAL | 9.8 | 0.8% | Jun 2, 2022 | SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege esc... |
| CVE-2021-33016 | CRITICAL | 9.8 | 0.9% | May 26, 2022 | An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 co... |
| CVE-2021-27779 | CRITICAL | 9.1 | 0.5% | May 25, 2022 | VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on co... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now