2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43142 | CRITICAL | 9.8 | 1.4% | Mar 30, 2022 | An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput. |
| CVE-2021-43118 | CRITICAL | 9.8 | 34.8% | Mar 29, 2022 | A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek V... |
| CVE-2021-42911 | CRITICAL | 9.8 | 3.3% | Mar 29, 2022 | A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor ... |
| CVE-2021-43110 | CRITICAL | 9.8 | 1.5% | Mar 29, 2022 | An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products. |
| CVE-2021-46743 | CRITICAL | 9.1 | 0.8% | Mar 29, 2022 | In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) hea... |
| CVE-2021-45865 | CRITICAL | 9.8 | 1.4% | Mar 29, 2022 | A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functio... |
| CVE-2021-25070 | CRITICAL | 9.8 | 1.6% | Mar 28, 2022 | The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in ... |
| CVE-2021-46433 | CRITICAL | 10 | 1.1% | Mar 28, 2022 | In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox t... |
| CVE-2021-45490 | CRITICAL | 9.1 | 1.1% | Mar 28, 2022 | The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 l... |
| CVE-2021-44617 | CRITICAL | 9.8 | 2.1% | Mar 28, 2022 | A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.... |
| CVE-2021-26600 | CRITICAL | 9.8 | 5.5% | Mar 28, 2022 | ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= inste... |
| CVE-2021-26599 | CRITICAL | 9.8 | 19.4% | Mar 28, 2022 | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. |
| CVE-2021-44127 | CRITICAL | 9.8 | 3.3% | Mar 27, 2022 | In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execut... |
| CVE-2021-26622 | CRITICAL | 10 | 2.9% | Mar 25, 2022 | An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was dis... |
| CVE-2021-26621 | CRITICAL | 9.8 | 1.6% | Mar 25, 2022 | An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this... |
| CVE-2021-43636 | CRITICAL | 9.8 | 1.0% | Mar 25, 2022 | Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function... |
| CVE-2021-43090 | CRITICAL | 9.8 | 1.9% | Mar 25, 2022 | An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function. |
| CVE-2021-43084 | CRITICAL | 9.8 | 0.9% | Mar 24, 2022 | An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter. |
| CVE-2021-43700 | CRITICAL | 9.8 | 1.1% | Mar 24, 2022 | An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8... |
| CVE-2021-31326 | CRITICAL | 9.8 | 2.2% | Mar 24, 2022 | D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parame... |
| CVE-2021-27476 | CRITICAL | 9.8 | 4.3% | Mar 23, 2022 | A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection... |
| CVE-2021-27472 | CRITICAL | 9.8 | 5.3% | Mar 23, 2022 | A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre... |
| CVE-2021-27470 | CRITICAL | 9.8 | 3.7% | Mar 23, 2022 | A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre ... |
| CVE-2021-27468 | CRITICAL | 9.8 | 3.4% | Mar 23, 2022 | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking p... |
| CVE-2021-27466 | CRITICAL | 9.8 | 3.7% | Mar 23, 2022 | A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCen... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now