2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-33274CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33271CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33270CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33269CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33268CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33267CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33266CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33265CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-43451CRITICAL9.8SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /...
CVE-2021-43685CRITICAL9.8libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/r...
CVE-2021-26334CRITICAL9.9The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may le...
CVE-2021-44280CRITICAL9.8attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the make...
CVE-2021-3994CRITICAL9.6django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3985CRITICAL9kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-36330CRITICAL9.8Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote ...
CVE-2021-43319CRITICAL9.8Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validat...
CVE-2021-42099CRITICAL9.8Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
CVE-2021-26612CRITICAL9.8An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remot...
CVE-2021-43202CRITICAL9.8In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
CVE-2021-41679CRITICAL9.8A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database...
CVE-2021-41678CRITICAL9.8A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database...
CVE-2021-41677CRITICAL9.8A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database...
CVE-2021-42545CRITICAL9.1An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7....
CVE-2021-42544CRITICAL9.8Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27...
CVE-2021-42115CRITICAL9.1Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now