2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30080 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | An issue was discovered in the route lookup process in beego before 1.12.11 that allows attackers to bypass access contr... |
| CVE-2021-28428 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media... |
| CVE-2021-33207 | CRITICAL | 9.8 | 1.6% | Apr 5, 2022 | The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570... |
| CVE-2021-33008 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requi... |
| CVE-2021-32986 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user... |
| CVE-2021-32984 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the... |
| CVE-2021-32980 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional sof... |
| CVE-2021-30064 | CRITICAL | 9.8 | 0.9% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ... |
| CVE-2021-32976 | CRITICAL | 9.8 | 2.6% | Apr 1, 2022 | Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may a... |
| CVE-2021-32974 | CRITICAL | 9.8 | 2.6% | Apr 1, 2022 | Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier m... |
| CVE-2021-32953 | CRITICAL | 9.8 | 1.2% | Apr 1, 2022 | An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’... |
| CVE-2021-32933 | CRITICAL | 9.8 | 1.2% | Apr 1, 2022 | An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command... |
| CVE-2021-27501 | CRITICAL | 9.8 | 0.9% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to res... |
| CVE-2021-27497 | CRITICAL | 9.8 | 0.8% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides suffi... |
| CVE-2021-26623 | CRITICAL | 9.8 | 1.1% | Apr 1, 2022 | A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter leng... |
| CVE-2021-23247 | CRITICAL | 9.8 | 1.7% | Apr 1, 2022 | A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote att... |
| CVE-2021-44135 | CRITICAL | 9.8 | 1.5% | Apr 1, 2022 | pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing. |
| CVE-2021-35117 | CRITICAL | 9.1 | 0.8% | Apr 1, 2022 | An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Sna... |
| CVE-2021-35088 | CRITICAL | 9.1 | 0.8% | Apr 1, 2022 | Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdrago... |
| CVE-2021-43722 | CRITICAL | 9.8 | 3.1% | Mar 31, 2022 | D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to fo... |
| CVE-2021-43479 | CRITICAL | 9.8 | 2.4% | Mar 31, 2022 | A Remote Code Execution (RCE) vulnerability exists in The-Secretary 2.5 via install.php. |
| CVE-2021-43484 | CRITICAL | 9.8 | 3.3% | Mar 31, 2022 | A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failu... |
| CVE-2021-43506 | CRITICAL | 9.8 | 1.6% | Mar 31, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter i... |
| CVE-2021-46009 | CRITICAL | 9.8 | 15.2% | Mar 30, 2022 | In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, ad... |
| CVE-2021-46007 | CRITICAL | 9.8 | 3.6% | Mar 30, 2022 | totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command,... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now