2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44525 | CRITICAL | 9.8 | 3.4% | Dec 20, 2021 | Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a fi... |
| CVE-2021-44676 | CRITICAL | 9.8 | 4.4% | Dec 20, 2021 | Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control detail... |
| CVE-2021-44675 | CRITICAL | 9.8 | 6.5% | Dec 20, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution du... |
| CVE-2021-44790 | CRITICAL | 9.8 | 97.1% | Dec 20, 2021 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from ... |
| CVE-2021-44732 | CRITICAL | 9.8 | 2.6% | Dec 20, 2021 | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_sessi... |
| CVE-2021-44164 | CRITICAL | 9.8 | 2.1% | Dec 20, 2021 | Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allo... |
| CVE-2021-44159 | CRITICAL | 9.8 | 3.4% | Dec 20, 2021 | 4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary fil... |
| CVE-2021-23803 | CRITICAL | 9.8 | 1.6% | Dec 17, 2021 | This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the securit... |
| CVE-2021-23797 | CRITICAL | 9.8 | 1.7% | Dec 17, 2021 | All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is. |
| CVE-2021-23450 | CRITICAL | 9.8 | 30.4% | Dec 17, 2021 | All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. |
| CVE-2021-40850 | CRITICAL | 9.8 | 0.9% | Dec 17, 2021 | TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.a... |
| CVE-2021-36779 | CRITICAL | 9.6 | 0.7% | Dec 17, 2021 | A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to exec... |
| CVE-2021-43837 | CRITICAL | 9.1 | 5.0% | Dec 16, 2021 | vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versio... |
| CVE-2021-45092 | CRITICAL | 9.8 | 40.0% | Dec 16, 2021 | Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi... |
| CVE-2021-43834 | CRITICAL | 9.8 | 1.0% | Dec 16, 2021 | eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh... |
| CVE-2021-44350 | CRITICAL | 9.8 | 1.4% | Dec 15, 2021 | SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php. |
| CVE-2021-4119 | CRITICAL | 9.8 | 26.9% | Dec 15, 2021 | bookstack is vulnerable to Improper Access Control |
| CVE-2021-27856 | CRITICAL | 9.8 | 5.6% | Dec 15, 2021 | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" ... |
| CVE-2021-43935 | CRITICAL | 9.8 | 1.1% | Dec 15, 2021 | The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulner... |
| CVE-2021-39655 | CRITICAL | 9.8 | 0.5% | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A |
| CVE-2021-39645 | CRITICAL | 9.8 | 0.5% | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A |
| CVE-2021-39644 | CRITICAL | 9.8 | 0.5% | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A |
| CVE-2021-39641 | CRITICAL | 9.8 | 0.5% | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A |
| CVE-2021-36888 | CRITICAL | 9.8 | 6.7% | Dec 15, 2021 | Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effe... |
| CVE-2021-0956 | CRITICAL | 9.8 | 1.2% | Dec 15, 2021 | In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now