2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28962HIGH7.2Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.
CVE-2021-46101HIGH7.5In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.
CVE-2021-44255HIGH7.2Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to uplo...
CVE-2021-23521HIGH7.8This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is c...
CVE-2021-23520CRITICAL9.8The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) vi...
CVE-2021-45079CRITICAL9.1In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticat...
CVE-2021-34805HIGH7.5An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau ...
CVE-2021-27971HIGH7.8Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.
CVE-2021-46660CRITICAL9.8Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.
CVE-2021-46659MEDIUM5.5MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to ...
CVE-2021-46658MEDIUM5.5save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_w...
CVE-2021-46657MEDIUM5.5get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
CVE-2021-4160MEDIUM5.9There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including...
CVE-2021-46448CRITICAL9.8H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=...
CVE-2021-46447MEDIUM5.4A cross-site scripting (XSS) vulnerability in H.H.G Multistore v5.1.0 and below allows attackers to execute arbitrary we...
CVE-2021-46446CRITICAL9.8H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad...
CVE-2021-46445CRITICAL9.8H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_...
CVE-2021-46444CRITICAL9.8H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad...
CVE-2021-44419HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...
CVE-2021-44418HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...
CVE-2021-44417HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...
CVE-2021-44416HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...
CVE-2021-44415HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...
CVE-2021-44414HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...
CVE-2021-44413HIGH7.7A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now