2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-47819CRITICAL9.8ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP ...
CVE-2021-47781CRITICAL9.8Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of serv...
CVE-2021-47774CRITICAL9.8Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers...
CVE-2021-47772CRITICAL9.810-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functiona...
CVE-2021-47753CRITICAL9.8phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arb...
CVE-2021-47744CRITICAL9.3Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes...
CVE-2021-47731CRITICAL9.8Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configura...
CVE-2021-47728CRITICAL9.8Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remo...
CVE-2021-47708CRITICAL9.3COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authenticatio...
CVE-2021-47707CRITICAL9.3COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclos...
CVE-2021-4470CRITICAL9.3TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd...
CVE-2021-4464CRITICAL9.3FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based bu...
CVE-2021-4462CRITICAL9.8Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthentica...
CVE-2021-4461CRITICAL9.3Seeyon Zhiyuan OA Web Application System versions up to and including 7.0 SP1 improperly decode and parse the `enc` para...
CVE-2021-4458CRITICAL9.8The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_aj...
CVE-2021-4457CRITICAL9.1The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywher...
CVE-2021-41691CRITICAL9.8A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TR...
CVE-2021-4455CRITICAL9.8The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi...
CVE-2021-27289CRITICAL9.1A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1...
CVE-2021-47667CRITICAL10An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenti...
CVE-2021-46686CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ...
CVE-2021-26102CRITICAL9.1A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remot...
CVE-2021-32589CRITICAL9.8A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below...
CVE-2021-38135CRITICAL9.8Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.
CVE-2021-38117CRITICAL9.8Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now