2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-23663CRITICAL9.8All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.
CVE-2021-23639CRITICAL9.8The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matte...
CVE-2021-23561CRITICAL9.8All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
CVE-2021-23463CRITICAL9.1The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via ...
CVE-2021-27983CRITICAL9.8Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
CVE-2021-38917CRITICAL9.1IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and...
CVE-2021-31746CRITICAL9.8Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in ...
CVE-2021-37934CRITICAL9.8Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterpris...
CVE-2021-35978CRITICAL9.8An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command exe...
CVE-2021-44228CRITICAL10Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in con...
CVE-2021-44514CRITICAL9.8OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
CVE-2021-43608CRITICAL9.8Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIM...
CVE-2021-43703CRITICAL9.8An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling Java...
CVE-2021-41695CRITICAL9.8An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .
CVE-2021-41694CRITICAL9.8An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in req...
CVE-2021-21954CRITICAL9.9A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of An...
CVE-2021-20146CRITICAL9.8An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affi...
CVE-2021-3817CRITICAL9.8wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
CVE-2021-4048CRITICAL9.1An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10....
CVE-2021-44529CRITICAL9.8A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut...
CVE-2021-43527CRITICAL9.8NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER...
CVE-2021-38503CRITICAL10The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such ...
CVE-2021-21951CRITICAL10An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security...
CVE-2021-21950CRITICAL10An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security...
CVE-2021-41025CRITICAL9.8Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.1...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now