2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-27464CRITICAL9.8The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacki...
CVE-2021-27462CRITICAL9.8A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre ...
CVE-2021-27460CRITICAL9.8Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deseriali...
CVE-2021-27428CRITICAL9.8GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervi...
CVE-2021-27426CRITICAL9.8GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Fac...
CVE-2021-38278CRITICAL9.8Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentCont...
CVE-2021-43736CRITICAL9.8CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule
CVE-2021-43735CRITICAL9.8CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.
CVE-2021-45756CRITICAL9.8Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request....
CVE-2021-41736CRITICAL9.8Faust v2.35.0 was discovered to contain a heap-buffer overflow in the function realPropagate() at propagate.cpp.
CVE-2021-43650CRITICAL9.8WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
CVE-2021-45809CRITICAL9.8GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GU...
CVE-2021-45878CRITICAL9.1Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the we...
CVE-2021-45877CRITICAL9.8Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /e...
CVE-2021-45876CRITICAL9.8Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of th...
CVE-2021-39384CRITICAL9.8DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.j...
CVE-2021-39383CRITICAL9.8DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysP...
CVE-2021-45835CRITICAL9.8The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the...
CVE-2021-45834CRITICAL9.8An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass...
CVE-2021-45967CRITICAL9.8An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To...
CVE-2021-45966CRITICAL9.8An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.p...
CVE-2021-44088CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacke...
CVE-2021-44087CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an ...
CVE-2021-45040CRITICAL9.8The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload...
CVE-2021-44906CRITICAL9.8Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now