2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33274 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33271 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33270 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33269 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33268 | CRITICAL | 9.8 | 3.9% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33267 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33266 | CRITICAL | 9.8 | 16.9% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33265 | CRITICAL | 9.8 | 13.7% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-43451 | CRITICAL | 9.8 | 2.1% | Dec 1, 2021 | SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /... |
| CVE-2021-43685 | CRITICAL | 9.8 | 1.2% | Dec 1, 2021 | libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/r... |
| CVE-2021-26334 | CRITICAL | 9.9 | 1.2% | Dec 1, 2021 | The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may le... |
| CVE-2021-44280 | CRITICAL | 9.8 | 1.9% | Dec 1, 2021 | attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the make... |
| CVE-2021-3994 | CRITICAL | 9.6 | 1.4% | Dec 1, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3985 | CRITICAL | 9 | 1.2% | Dec 1, 2021 | kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-36330 | CRITICAL | 9.8 | 1.2% | Nov 30, 2021 | Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote ... |
| CVE-2021-43319 | CRITICAL | 9.8 | 21.4% | Nov 30, 2021 | Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validat... |
| CVE-2021-42099 | CRITICAL | 9.8 | 6.5% | Nov 30, 2021 | Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. |
| CVE-2021-26612 | CRITICAL | 9.8 | 1.2% | Nov 30, 2021 | An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remot... |
| CVE-2021-43202 | CRITICAL | 9.8 | 1.1% | Nov 30, 2021 | In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. |
| CVE-2021-41679 | CRITICAL | 9.8 | 1.3% | Nov 30, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database... |
| CVE-2021-41678 | CRITICAL | 9.8 | 1.3% | Nov 30, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database... |
| CVE-2021-41677 | CRITICAL | 9.8 | 1.3% | Nov 30, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database... |
| CVE-2021-42545 | CRITICAL | 9.1 | 1.1% | Nov 30, 2021 | An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.... |
| CVE-2021-42544 | CRITICAL | 9.8 | 1.4% | Nov 30, 2021 | Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27... |
| CVE-2021-42115 | CRITICAL | 9.1 | 1.2% | Nov 30, 2021 | Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now