2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-41754CRITICAL9.8dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.
CVE-2021-27786CRITICAL9.8Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This requ...
CVE-2021-40589CRITICAL9.8ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fil...
CVE-2021-42890CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file...
CVE-2021-42888CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file ...
CVE-2021-42887CRITICAL9.8In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
CVE-2021-42885CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file gl...
CVE-2021-42884CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file g...
CVE-2021-33473CRITICAL9.1An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when...
CVE-2021-42875CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the ...
CVE-2021-45983CRITICAL9.8NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
CVE-2021-45981CRITICAL9.8NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
CVE-2021-44098CRITICAL9.8EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remot...
CVE-2021-44097CRITICAL9.8EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This a...
CVE-2021-44096CRITICAL9.8EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action...
CVE-2021-44095CRITICAL9.8A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a ...
CVE-2021-42872CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code...
CVE-2021-34084CRITICAL9.8OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to ex...
CVE-2021-34082CRITICAL9.8OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7...
CVE-2021-34080CRITICAL9.8OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands v...
CVE-2021-34079CRITICAL9.8OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands ...
CVE-2021-26634CRITICAL9.8SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and...
CVE-2021-26633CRITICAL9.8SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege esc...
CVE-2021-33016CRITICAL9.8An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 co...
CVE-2021-27779CRITICAL9.1VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on co...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now