2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-44949CRITICAL9.8glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
CVE-2021-45015CRITICAL9.1taocms 3.0.2 is vulnerable to arbitrary file deletion via taocms\include\Model\file.php from line 60 to line 72.
CVE-2021-45014CRITICAL9.8There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id:action=cms&ctrl=update&...
CVE-2021-44538CRITICAL9.8The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session obje...
CVE-2021-44935CRITICAL9.1glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attack...
CVE-2021-44524CRITICAL9.8A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S...
CVE-2021-44523CRITICAL9.1A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S...
CVE-2021-24045CRITICAL9.8A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to...
CVE-2021-39063CRITICAL9.1IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attac...
CVE-2021-32024CRITICAL9.8A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an ...
CVE-2021-39065CRITICAL9.8IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the ...
CVE-2021-39052CRITICAL9.8IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console wit...
CVE-2021-22279CRITICAL9.8A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and mod...
CVE-2021-44966CRITICAL9.8SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An ...
CVE-2021-43117CRITICAL9.8fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.
CVE-2021-24951CRITICAL9.8The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in ...
CVE-2021-24946CRITICAL9.8The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before usi...
CVE-2021-24922CRITICAL9The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as w...
CVE-2021-24863CRITICAL9.8The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before ...
CVE-2021-24857CRITICAL9.8The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which ...
CVE-2021-44152CRITICAL9.8An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a...
CVE-2021-44847CRITICAL9.8A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2....
CVE-2021-44833CRITICAL9.8The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
CVE-2021-44515CRITICAL9.8Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server...
CVE-2021-23700CRITICAL9.8All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now