2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-0889CRITICAL9.8In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to ...
CVE-2021-42216CRITICAL9.8A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
CVE-2021-44655CRITICAL9.8Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. A...
CVE-2021-44653CRITICAL9.8Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel auth...
CVE-2021-43907CRITICAL9.8Visual Studio Code WSL Extension Remote Code Execution Vulnerability
CVE-2021-43905CRITICAL9.6Microsoft Office app Remote Code Execution Vulnerability
CVE-2021-43899CRITICAL9.8Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability
CVE-2021-43882CRITICAL9.8Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-43225CRITICAL9.8Bot Framework SDK Remote Code Execution Vulnerability
CVE-2021-43217CRITICAL9.8Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
CVE-2021-43215CRITICAL9.8iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
CVE-2021-43214CRITICAL9.8Web Media Extensions Remote Code Execution Vulnerability
CVE-2021-42313CRITICAL10Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42311CRITICAL10Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42310CRITICAL9.8Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-43113CRITICAL9.8iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mi...
CVE-2021-42945CRITICAL9.8A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.
CVE-2021-41560CRITICAL9.8OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUti...
CVE-2021-41844CRITICAL9.8Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.
CVE-2021-45046CRITICAL9It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configu...
CVE-2021-40883CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
CVE-2021-44042CRITICAL9.8An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the...
CVE-2021-44041CRITICAL9.8UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget a...
CVE-2021-44231CRITICAL9.8Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An att...
CVE-2021-42064CRITICAL9.8If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterize...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now