2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21874 | CRITICAL | 9.1 | 2.9% | Dec 22, 2021 | A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can mak... |
| CVE-2021-21873 | CRITICAL | 9.1 | 2.9% | Dec 22, 2021 | A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can mak... |
| CVE-2021-21872 | CRITICAL | 9.9 | 6.1% | Dec 22, 2021 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix Premi... |
| CVE-2021-44659 | CRITICAL | 9.8 | 2.5% | Dec 22, 2021 | Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action... |
| CVE-2021-43631 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment... |
| CVE-2021-43629 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php. |
| CVE-2021-43628 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php. |
| CVE-2021-43157 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php. |
| CVE-2021-43155 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php. |
| CVE-2021-37706 | CRITICAL | 9.8 | 4.6% | Dec 22, 2021 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2021-40612 | CRITICAL | 9.8 | 2.0% | Dec 22, 2021 | An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/appl... |
| CVE-2021-45459 | CRITICAL | 9.8 | 4.1% | Dec 22, 2021 | lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter. |
| CVE-2021-44031 | CRITICAL | 9.8 | 2.1% | Dec 22, 2021 | An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksetting... |
| CVE-2021-44029 | CRITICAL | 9.8 | 0.9% | Dec 22, 2021 | An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remo... |
| CVE-2021-27453 | CRITICAL | 9.8 | 1.0% | Dec 21, 2021 | Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application,... |
| CVE-2021-27451 | CRITICAL | 9.8 | 0.8% | Dec 21, 2021 | Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an... |
| CVE-2021-27447 | CRITICAL | 9.8 | 2.3% | Dec 21, 2021 | Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute ar... |
| CVE-2021-36336 | CRITICAL | 9.8 | 1.7% | Dec 21, 2021 | Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticat... |
| CVE-2021-45090 | CRITICAL | 9.8 | 2.9% | Dec 21, 2021 | Stormshield Endpoint Security before 2.1.2 allows remote code execution. |
| CVE-2021-4139 | CRITICAL | 9 | 0.9% | Dec 21, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-45255 | CRITICAL | 9.8 | 1.5% | Dec 21, 2021 | The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payl... |
| CVE-2021-45253 | CRITICAL | 9.8 | 1.2% | Dec 21, 2021 | The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL inje... |
| CVE-2021-45252 | CRITICAL | 9.8 | 1.2% | Dec 21, 2021 | Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications... |
| CVE-2021-24849 | CRITICAL | 9.8 | 8.5% | Dec 21, 2021 | The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticate... |
| CVE-2021-43439 | CRITICAL | 9.8 | 3.4% | Dec 20, 2021 | RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now