2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-37589HIGH7.5Virtua Cobranca before 12R allows SQL Injection on the login page.
CVE-2021-39947HIGH7.5In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2...
CVE-2021-41932HIGH8.8A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to...
CVE-2021-42893HIGH7.5In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization th...
CVE-2021-42891HIGH7.5In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
CVE-2021-42889HIGH7.5In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without author...
CVE-2021-42886HIGH7.5TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib conf...
CVE-2021-42877HIGH7.5TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_...
CVE-2021-45982HIGH8.8NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
CVE-2021-44080HIGH7.2A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged...
CVE-2021-43308HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package,...
CVE-2021-43307HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an at...
CVE-2021-43306HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when ...
CVE-2021-42204HIGH7.8An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() locate...
CVE-2021-42203HIGH7.8An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_Defin...
CVE-2021-42201HIGH7.8An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located...
CVE-2021-42199HIGH7.8An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_Defi...
CVE-2021-42197HIGH7.8An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allo...
CVE-2021-42195HIGH7.8An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() loc...
CVE-2021-40186HIGH7.5The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, fo...
CVE-2021-34083HIGH8.1Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON...
CVE-2021-34081HIGH8.8OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via ...
CVE-2021-34078HIGH8.8lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scan...
CVE-2021-33615HIGH7.5RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.
CVE-2021-33254HIGH7.5An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a d...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now