2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44949 | CRITICAL | 9.8 | 1.1% | Dec 14, 2021 | glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php. |
| CVE-2021-45015 | CRITICAL | 9.1 | 1.2% | Dec 14, 2021 | taocms 3.0.2 is vulnerable to arbitrary file deletion via taocms\include\Model\file.php from line 60 to line 72. |
| CVE-2021-45014 | CRITICAL | 9.8 | 1.1% | Dec 14, 2021 | There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id:action=cms&ctrl=update&... |
| CVE-2021-44538 | CRITICAL | 9.8 | 1.9% | Dec 14, 2021 | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session obje... |
| CVE-2021-44935 | CRITICAL | 9.1 | 0.5% | Dec 14, 2021 | glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attack... |
| CVE-2021-44524 | CRITICAL | 9.8 | 1.6% | Dec 14, 2021 | A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S... |
| CVE-2021-44523 | CRITICAL | 9.1 | 1.4% | Dec 14, 2021 | A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S... |
| CVE-2021-24045 | CRITICAL | 9.8 | 1.2% | Dec 13, 2021 | A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to... |
| CVE-2021-39063 | CRITICAL | 9.1 | 0.7% | Dec 13, 2021 | IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attac... |
| CVE-2021-32024 | CRITICAL | 9.8 | 1.8% | Dec 13, 2021 | A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an ... |
| CVE-2021-39065 | CRITICAL | 9.8 | 2.2% | Dec 13, 2021 | IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the ... |
| CVE-2021-39052 | CRITICAL | 9.8 | 1.1% | Dec 13, 2021 | IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console wit... |
| CVE-2021-22279 | CRITICAL | 9.8 | 1.4% | Dec 13, 2021 | A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and mod... |
| CVE-2021-44966 | CRITICAL | 9.8 | 2.1% | Dec 13, 2021 | SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An ... |
| CVE-2021-43117 | CRITICAL | 9.8 | 2.1% | Dec 13, 2021 | fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access. |
| CVE-2021-24951 | CRITICAL | 9.8 | 1.6% | Dec 13, 2021 | The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in ... |
| CVE-2021-24946 | CRITICAL | 9.8 | 73.4% | Dec 13, 2021 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before usi... |
| CVE-2021-24922 | CRITICAL | 9 | 0.5% | Dec 13, 2021 | The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as w... |
| CVE-2021-24863 | CRITICAL | 9.8 | 1.6% | Dec 13, 2021 | The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before ... |
| CVE-2021-24857 | CRITICAL | 9.8 | 1.8% | Dec 13, 2021 | The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which ... |
| CVE-2021-44152 | CRITICAL | 9.8 | 58.6% | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a... |
| CVE-2021-44847 | CRITICAL | 9.8 | 4.0% | Dec 13, 2021 | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.... |
| CVE-2021-44833 | CRITICAL | 9.8 | 1.6% | Dec 12, 2021 | The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file. |
| CVE-2021-44515 | CRITICAL | 9.8 | 99.9% | Dec 12, 2021 | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server... |
| CVE-2021-23700 | CRITICAL | 9.8 | 1.2% | Dec 10, 2021 | All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now