2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-44525CRITICAL9.8Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a fi...
CVE-2021-44676CRITICAL9.8Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control detail...
CVE-2021-44675CRITICAL9.8Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution du...
CVE-2021-44790CRITICAL9.8A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from ...
CVE-2021-44732CRITICAL9.8Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_sessi...
CVE-2021-44164CRITICAL9.8Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allo...
CVE-2021-44159CRITICAL9.84MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary fil...
CVE-2021-23803CRITICAL9.8This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the securit...
CVE-2021-23797CRITICAL9.8All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.
CVE-2021-23450CRITICAL9.8All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
CVE-2021-40850CRITICAL9.8TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.a...
CVE-2021-36779CRITICAL9.6A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to exec...
CVE-2021-43837CRITICAL9.1vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versio...
CVE-2021-45092CRITICAL9.8Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi...
CVE-2021-43834CRITICAL9.8eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh...
CVE-2021-44350CRITICAL9.8SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.
CVE-2021-4119CRITICAL9.8bookstack is vulnerable to Improper Access Control
CVE-2021-27856CRITICAL9.8FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" ...
CVE-2021-43935CRITICAL9.8The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulner...
CVE-2021-39655CRITICAL9.8Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A
CVE-2021-39645CRITICAL9.8Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A
CVE-2021-39644CRITICAL9.8Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A
CVE-2021-39641CRITICAL9.8Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A
CVE-2021-36888CRITICAL9.8Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effe...
CVE-2021-0956CRITICAL9.8In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now