2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-46448CRITICAL9.8H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=...
CVE-2021-46446CRITICAL9.8H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad...
CVE-2021-46445CRITICAL9.8H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_...
CVE-2021-46444CRITICAL9.8H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad...
CVE-2021-23760CRITICAL9.8The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow ...
CVE-2021-23558CRITICAL9.8The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Not...
CVE-2021-23484CRITICAL9.8The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can le...
CVE-2021-40409CRITICAL9.8An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-40408CRITICAL9.8An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136...
CVE-2021-22820CRITICAL9.8A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized ...
CVE-2021-44971CRITICAL9.8Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmw...
CVE-2021-41609CRITICAL9.8SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows ...
CVE-2021-45899CRITICAL9.8SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
CVE-2021-45898CRITICAL9.8SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
CVE-2021-45435CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the ...
CVE-2021-44249CRITICAL9.8Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login por...
CVE-2021-46428CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versi...
CVE-2021-46427CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Mast...
CVE-2021-46377CRITICAL9.8There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser
CVE-2021-32840CRITICAL9.8SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` m...
CVE-2021-46386CRITICAL9.8File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafte...
CVE-2021-46560CRITICAL9.8The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.
CVE-2021-36294CRITICAL9.8Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthen...
CVE-2021-43799CRITICAL9.8Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In version...
CVE-2021-43298CRITICAL9.8The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now