2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-30080CRITICAL9.8An issue was discovered in the route lookup process in beego before 1.12.11 that allows attackers to bypass access contr...
CVE-2021-28428CRITICAL9.8File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media...
CVE-2021-33207CRITICAL9.8The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570...
CVE-2021-33008CRITICAL9.8AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requi...
CVE-2021-32986CRITICAL9.8After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user...
CVE-2021-32984CRITICAL9.8All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the...
CVE-2021-32980CRITICAL9.8Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional sof...
CVE-2021-30064CRITICAL9.8On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ...
CVE-2021-32976CRITICAL9.8Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may a...
CVE-2021-32974CRITICAL9.8Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier m...
CVE-2021-32953CRITICAL9.8An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’...
CVE-2021-32933CRITICAL9.8An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command...
CVE-2021-27501CRITICAL9.8Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to res...
CVE-2021-27497CRITICAL9.8Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides suffi...
CVE-2021-26623CRITICAL9.8A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter leng...
CVE-2021-23247CRITICAL9.8A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote att...
CVE-2021-44135CRITICAL9.8pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
CVE-2021-35117CRITICAL9.1An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Sna...
CVE-2021-35088CRITICAL9.1Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdrago...
CVE-2021-43722CRITICAL9.8D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to fo...
CVE-2021-43479CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in The-Secretary 2.5 via install.php.
CVE-2021-43484CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failu...
CVE-2021-43506CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter i...
CVE-2021-46009CRITICAL9.8In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, ad...
CVE-2021-46007CRITICAL9.8totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command,...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now