2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-47819 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP ... |
| CVE-2021-47781 | CRITICAL | 9.8 | 0.3% | Jan 15, 2026 | Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of serv... |
| CVE-2021-47774 | CRITICAL | 9.8 | 0.5% | Jan 15, 2026 | Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers... |
| CVE-2021-47772 | CRITICAL | 9.8 | 0.6% | Jan 15, 2026 | 10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functiona... |
| CVE-2021-47753 | CRITICAL | 9.8 | 0.7% | Jan 15, 2026 | phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arb... |
| CVE-2021-47744 | CRITICAL | 9.3 | 0.3% | Dec 31, 2025 | Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes... |
| CVE-2021-47731 | CRITICAL | 9.8 | 0.4% | Dec 9, 2025 | Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configura... |
| CVE-2021-47728 | CRITICAL | 9.8 | 2.3% | Dec 9, 2025 | Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remo... |
| CVE-2021-47708 | CRITICAL | 9.3 | 0.4% | Dec 9, 2025 | COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authenticatio... |
| CVE-2021-47707 | CRITICAL | 9.3 | 0.3% | Dec 9, 2025 | COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclos... |
| CVE-2021-4470 | CRITICAL | 9.3 | 0.9% | Nov 14, 2025 | TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd... |
| CVE-2021-4464 | CRITICAL | 9.3 | 1.8% | Nov 12, 2025 | FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based bu... |
| CVE-2021-4462 | CRITICAL | 9.8 | 3.0% | Nov 10, 2025 | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthentica... |
| CVE-2021-4461 | CRITICAL | 9.3 | 0.6% | Oct 30, 2025 | Seeyon Zhiyuan OA Web Application System versions up to and including 7.0 SP1 improperly decode and parse the `enc` para... |
| CVE-2021-4458 | CRITICAL | 9.8 | 0.4% | Jul 12, 2025 | The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_aj... |
| CVE-2021-4457 | CRITICAL | 9.1 | 0.4% | Jun 25, 2025 | The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywher... |
| CVE-2021-41691 | CRITICAL | 9.8 | 1.7% | Jun 24, 2025 | A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TR... |
| CVE-2021-4455 | CRITICAL | 9.8 | 0.6% | Apr 19, 2025 | The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi... |
| CVE-2021-27289 | CRITICAL | 9.1 | 0.7% | Apr 15, 2025 | A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1... |
| CVE-2021-47667 | CRITICAL | 10 | 26.3% | Apr 5, 2025 | An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenti... |
| CVE-2021-46686 | CRITICAL | 9.8 | 1.4% | Feb 18, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ... |
| CVE-2021-26102 | CRITICAL | 9.1 | 16.4% | Dec 19, 2024 | A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remot... |
| CVE-2021-32589 | CRITICAL | 9.8 | 8.7% | Dec 19, 2024 | A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below... |
| CVE-2021-38135 | CRITICAL | 9.8 | 0.4% | Nov 22, 2024 | Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000. |
| CVE-2021-38117 | CRITICAL | 9.8 | 1.1% | Nov 22, 2024 | Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now