2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-43142CRITICAL9.8An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
CVE-2021-43118CRITICAL9.8A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek V...
CVE-2021-42911CRITICAL9.8A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor ...
CVE-2021-43110CRITICAL9.8An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.
CVE-2021-46743CRITICAL9.1In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) hea...
CVE-2021-45865CRITICAL9.8A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functio...
CVE-2021-25070CRITICAL9.8The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in ...
CVE-2021-46433CRITICAL10In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox t...
CVE-2021-45490CRITICAL9.1The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 l...
CVE-2021-44617CRITICAL9.8A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest....
CVE-2021-26600CRITICAL9.8ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= inste...
CVE-2021-26599CRITICAL9.8ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
CVE-2021-44127CRITICAL9.8In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execut...
CVE-2021-26622CRITICAL10An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was dis...
CVE-2021-26621CRITICAL9.8An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this...
CVE-2021-43636CRITICAL9.8Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function...
CVE-2021-43090CRITICAL9.8An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.
CVE-2021-43084CRITICAL9.8An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.
CVE-2021-43700CRITICAL9.8An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8...
CVE-2021-31326CRITICAL9.8D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parame...
CVE-2021-27476CRITICAL9.8A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection...
CVE-2021-27472CRITICAL9.8A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre...
CVE-2021-27470CRITICAL9.8A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre ...
CVE-2021-27468CRITICAL9.8The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking p...
CVE-2021-27466CRITICAL9.8A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCen...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now