2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-21874CRITICAL9.1A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can mak...
CVE-2021-21873CRITICAL9.1A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can mak...
CVE-2021-21872CRITICAL9.9An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix Premi...
CVE-2021-44659CRITICAL9.8Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action...
CVE-2021-43631CRITICAL9.8Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment...
CVE-2021-43629CRITICAL9.8Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
CVE-2021-43628CRITICAL9.8Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
CVE-2021-43157CRITICAL9.8Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
CVE-2021-43155CRITICAL9.8Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.
CVE-2021-37706CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2021-40612CRITICAL9.8An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/appl...
CVE-2021-45459CRITICAL9.8lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
CVE-2021-44031CRITICAL9.8An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksetting...
CVE-2021-44029CRITICAL9.8An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remo...
CVE-2021-27453CRITICAL9.8Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application,...
CVE-2021-27451CRITICAL9.8Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an...
CVE-2021-27447CRITICAL9.8Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute ar...
CVE-2021-36336CRITICAL9.8Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticat...
CVE-2021-45090CRITICAL9.8Stormshield Endpoint Security before 2.1.2 allows remote code execution.
CVE-2021-4139CRITICAL9pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-45255CRITICAL9.8The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payl...
CVE-2021-45253CRITICAL9.8The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL inje...
CVE-2021-45252CRITICAL9.8Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications...
CVE-2021-24849CRITICAL9.8The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticate...
CVE-2021-43439CRITICAL9.8RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now