2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43931 | CRITICAL | 9.8 | 1.4% | Dec 6, 2021 | The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result ... |
| CVE-2021-39890 | CRITICAL | 9.8 | 1.0% | Dec 6, 2021 | It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 a... |
| CVE-2021-24943 | CRITICAL | 9.8 | 7.5% | Dec 6, 2021 | The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the... |
| CVE-2021-24931 | CRITICAL | 9.8 | 78.8% | Dec 6, 2021 | The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id paramet... |
| CVE-2021-24866 | CRITICAL | 9.8 | 1.6% | Dec 6, 2021 | The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before ... |
| CVE-2021-43044 | CRITICAL | 9.8 | 1.9% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak d... |
| CVE-2021-43042 | CRITICAL | 9.8 | 2.9% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer... |
| CVE-2021-43036 | CRITICAL | 9.8 | 1.9% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest accou... |
| CVE-2021-43035 | CRITICAL | 9.8 | 3.3% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabil... |
| CVE-2021-43033 | CRITICAL | 9.8 | 6.0% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon w... |
| CVE-2021-35414 | CRITICAL | 9.8 | 1.8% | Dec 3, 2021 | Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload... |
| CVE-2021-44349 | CRITICAL | 9.8 | 1.1% | Dec 3, 2021 | SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.cl... |
| CVE-2021-44348 | CRITICAL | 9.8 | 1.1% | Dec 3, 2021 | SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class... |
| CVE-2021-35346 | CRITICAL | 9.8 | 1.7% | Dec 3, 2021 | tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function HevcSpsUnit::short_term_ref_pic_... |
| CVE-2021-35344 | CRITICAL | 9.8 | 1.7% | Dec 3, 2021 | tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function BitStreamReader::getCurVal in bi... |
| CVE-2021-23758 | CRITICAL | 9.8 | 88.8% | Dec 3, 2021 | All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserial... |
| CVE-2021-44352 | CRITICAL | 9.8 | 13.4% | Dec 3, 2021 | A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in... |
| CVE-2021-44347 | CRITICAL | 9.8 | 1.1% | Dec 3, 2021 | SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php. |
| CVE-2021-43676 | CRITICAL | 9.8 | 1.4% | Dec 3, 2021 | matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php. |
| CVE-2021-44278 | CRITICAL | 9.8 | 1.4% | Dec 3, 2021 | Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php. |
| CVE-2021-43674 | CRITICAL | 9.8 | 1.4% | Dec 3, 2021 | ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only ... |
| CVE-2021-28237 | CRITICAL | 9.8 | 1.4% | Dec 2, 2021 | LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13. |
| CVE-2021-23264 | CRITICAL | 9.1 | 1.1% | Dec 2, 2021 | Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete... |
| CVE-2021-43679 | CRITICAL | 9.8 | 1.6% | Dec 2, 2021 | ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php. |
| CVE-2021-26777 | CRITICAL | 9.8 | 2.4% | Dec 2, 2021 | Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concent... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now