2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-22823CRITICAL9.1A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file...
CVE-2021-22805CRITICAL9.1A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file...
CVE-2021-22803CRITICAL9.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution...
CVE-2021-22802CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution du...
CVE-2021-22801CRITICAL9.8A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the s...
CVE-2021-42940CRITICAL9.9A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allow...
CVE-2021-38679CRITICAL9.8An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this v...
CVE-2021-44521CRITICAL9.1When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user...
CVE-2021-35068CRITICAL9.8Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer ...
CVE-2021-45364CRITICAL9.8A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor in...
CVE-2021-25992CRITICAL9.8In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It ...
CVE-2021-39997CRITICAL9.8There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this ...
CVE-2021-39994CRITICAL9.8There is an arbitrary address access vulnerability with the product line test code.Successful exploitation of this vulne...
CVE-2021-26616CRITICAL9.8An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand ar...
CVE-2021-36302CRITICAL9.9All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A re...
CVE-2021-45331CRITICAL9.8An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. I...
CVE-2021-45330CRITICAL9.8An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not...
CVE-2021-45327CRITICAL9.8Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable a...
CVE-2021-25114CRITICAL9.8The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (avail...
CVE-2021-43927CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Managemen...
CVE-2021-43926CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun...
CVE-2021-43925CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun...
CVE-2021-41816CRITICAL9.8CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a lo...
CVE-2021-38172CRITICAL9.8perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.)
CVE-2021-44779CRITICAL9.8Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3),...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now