2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-24867CRITICAL9.8Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website bei...
CVE-2021-29656CRITICAL9.8Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.
CVE-2021-29655CRITICAL9.8Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.
CVE-2021-46110CRITICAL9.8Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email an...
CVE-2021-46063CRITICAL9.1MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management ...
CVE-2021-23702CRITICAL9.8The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend.
CVE-2021-46036CRITICAL9.8An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to ex...
CVE-2021-45401CRITICAL9.8A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.0...
CVE-2021-3657CRITICAL9.8A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals...
CVE-2021-26619CRITICAL9.1An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can u...
CVE-2021-26618CRITICAL9.8An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers u...
CVE-2021-20325CRITICAL9.8Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5...
CVE-2021-46319CRITICAL9.8Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-...
CVE-2021-46315CRITICAL9.8Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846...
CVE-2021-46314CRITICAL9.8A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router...
CVE-2021-45382CRITICAL9.8A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L...
CVE-2021-44868CRITICAL9.8A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do
CVE-2021-43303CRITICAL9.8Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer o...
CVE-2021-43302CRITICAL9.1Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause...
CVE-2021-43301CRITICAL9.8Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a...
CVE-2021-43300CRITICAL9.8Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a b...
CVE-2021-43299CRITICAL9.8Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buf...
CVE-2021-3242CRITICAL9.8DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.
CVE-2021-3781CRITICAL9.9A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting ...
CVE-2021-3773CRITICAL9.8A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for furthe...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now