2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-36205CRITICAL9.8Under certain circumstances the session token is not cleared on logout.
CVE-2021-40386CRITICAL9.8Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
CVE-2021-40422CRITICAL10An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway S...
CVE-2021-40390CRITICAL9.8An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specia...
CVE-2021-43290CRITICAL9.8An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a ma...
CVE-2021-42136CRITICAL9A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows...
CVE-2021-22795CRITICAL9.8A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists...
CVE-2021-22794CRITICAL9.8A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could ...
CVE-2021-43741CRITICAL9.8CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicio...
CVE-2021-31805CRITICAL9.8The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attribu...
CVE-2021-46742CRITICAL9.1The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful e...
CVE-2021-38125CRITICAL9.8Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.0...
CVE-2021-37291CRITICAL9.8An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id...
CVE-2021-32157CRITICAL9.6A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CVE-2021-36288CRITICAL9.1Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated...
CVE-2021-36287CRITICAL9.8Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which ...
CVE-2021-43517CRITICAL9.8FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port whe...
CVE-2021-43474CRITICAL9.8An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 functio...
CVE-2021-43453CRITICAL9.8A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in p...
CVE-2021-43421CRITICAL9.8A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remot...
CVE-2021-46419CRITICAL9.1An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil...
CVE-2021-26114CRITICAL9.8Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may...
CVE-2021-26112CRITICAL9.8Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpret...
CVE-2021-41752CRITICAL9.8Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due t...
CVE-2021-41751CRITICAL9.8Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now