2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-46013CRITICAL9.8An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can ...
CVE-2021-41807CRITICAL9.8Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of u...
CVE-2021-29215CRITICAL9.8A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the T...
CVE-2021-38697CRITICAL9.8SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files w...
CVE-2021-22566CRITICAL9.8An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as exe...
CVE-2021-44757CRITICAL9.1Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypas...
CVE-2021-4171CRITICAL9.8calibre-web is vulnerable to Business Logic Errors
CVE-2021-33963CRITICAL9.8China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by P...
CVE-2021-24044CRITICAL9.8By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter func...
CVE-2021-44530CRITICAL9.8An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2...
CVE-2021-39623CRITICAL9.8In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This co...
CVE-2021-28506CRITICAL9.1An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentic...
CVE-2021-1049CRITICAL9.8Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722
CVE-2021-45468CRITICAL9.8Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encodin...
CVE-2021-33962CRITICAL9.8China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /ap...
CVE-2021-38692CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If ...
CVE-2021-38691CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If ...
CVE-2021-38690CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If ...
CVE-2021-38689CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If ...
CVE-2021-38682CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If ...
CVE-2021-34993CRITICAL9.8This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.2...
CVE-2021-40722CRITICAL9.8AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) i...
CVE-2021-33046CRITICAL9.8Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerab...
CVE-2021-45807CRITICAL9.8jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
CVE-2021-45411CRITICAL9.8In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now