2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-43931CRITICAL9.8The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result ...
CVE-2021-39890CRITICAL9.8It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 a...
CVE-2021-24943CRITICAL9.8The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the...
CVE-2021-24931CRITICAL9.8The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id paramet...
CVE-2021-24866CRITICAL9.8The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before ...
CVE-2021-43044CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak d...
CVE-2021-43042CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer...
CVE-2021-43036CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest accou...
CVE-2021-43035CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabil...
CVE-2021-43033CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon w...
CVE-2021-35414CRITICAL9.8Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload...
CVE-2021-44349CRITICAL9.8SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.cl...
CVE-2021-44348CRITICAL9.8SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class...
CVE-2021-35346CRITICAL9.8tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function HevcSpsUnit::short_term_ref_pic_...
CVE-2021-35344CRITICAL9.8tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function BitStreamReader::getCurVal in bi...
CVE-2021-23758CRITICAL9.8All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserial...
CVE-2021-44352CRITICAL9.8A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in...
CVE-2021-44347CRITICAL9.8SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php.
CVE-2021-43676CRITICAL9.8matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
CVE-2021-44278CRITICAL9.8Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.
CVE-2021-43674CRITICAL9.8ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only ...
CVE-2021-28237CRITICAL9.8LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
CVE-2021-23264CRITICAL9.1Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete...
CVE-2021-43679CRITICAL9.8ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.
CVE-2021-26777CRITICAL9.8Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concent...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now