2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46448 | CRITICAL | 9.8 | 1.2% | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=... |
| CVE-2021-46446 | CRITICAL | 9.8 | 1.2% | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad... |
| CVE-2021-46445 | CRITICAL | 9.8 | 1.2% | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_... |
| CVE-2021-46444 | CRITICAL | 9.8 | 1.2% | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad... |
| CVE-2021-23760 | CRITICAL | 9.8 | 1.7% | Jan 28, 2022 | The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow ... |
| CVE-2021-23558 | CRITICAL | 9.8 | 1.6% | Jan 28, 2022 | The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Not... |
| CVE-2021-23484 | CRITICAL | 9.8 | 2.1% | Jan 28, 2022 | The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can le... |
| CVE-2021-40409 | CRITICAL | 9.8 | 3.7% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-40408 | CRITICAL | 9.8 | 3.7% | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136... |
| CVE-2021-22820 | CRITICAL | 9.8 | 1.1% | Jan 28, 2022 | A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized ... |
| CVE-2021-44971 | CRITICAL | 9.8 | 2.6% | Jan 28, 2022 | Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmw... |
| CVE-2021-41609 | CRITICAL | 9.8 | 2.1% | Jan 28, 2022 | SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows ... |
| CVE-2021-45899 | CRITICAL | 9.8 | 2.2% | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. |
| CVE-2021-45898 | CRITICAL | 9.8 | 1.1% | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. |
| CVE-2021-45435 | CRITICAL | 9.8 | 1.1% | Jan 28, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the ... |
| CVE-2021-44249 | CRITICAL | 9.8 | 1.8% | Jan 28, 2022 | Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login por... |
| CVE-2021-46428 | CRITICAL | 9.8 | 3.2% | Jan 27, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versi... |
| CVE-2021-46427 | CRITICAL | 9.8 | 2.0% | Jan 27, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Mast... |
| CVE-2021-46377 | CRITICAL | 9.8 | 1.0% | Jan 27, 2022 | There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser |
| CVE-2021-32840 | CRITICAL | 9.8 | 2.0% | Jan 26, 2022 | SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` m... |
| CVE-2021-46386 | CRITICAL | 9.8 | 3.1% | Jan 26, 2022 | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafte... |
| CVE-2021-46560 | CRITICAL | 9.8 | 3.6% | Jan 26, 2022 | The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage. |
| CVE-2021-36294 | CRITICAL | 9.8 | 1.6% | Jan 25, 2022 | Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthen... |
| CVE-2021-43799 | CRITICAL | 9.8 | 5.4% | Jan 25, 2022 | Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In version... |
| CVE-2021-43298 | CRITICAL | 9.8 | 2.3% | Jan 25, 2022 | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now