2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3769 | CRITICAL | 9.8 | 0.9% | Nov 30, 2021 | # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P`... |
| CVE-2021-3727 | CRITICAL | 9.8 | 1.0% | Nov 30, 2021 | # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes fro... |
| CVE-2021-3726 | CRITICAL | 9.8 | 0.8% | Nov 30, 2021 | # Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` ... |
| CVE-2021-44427 | CRITICAL | 9.8 | 50.6% | Nov 29, 2021 | An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow... |
| CVE-2021-43691 | CRITICAL | 9.8 | 1.5% | Nov 29, 2021 | tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The varia... |
| CVE-2021-43693 | CRITICAL | 9.8 | 1.2% | Nov 29, 2021 | vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php. |
| CVE-2021-24915 | CRITICAL | 9.8 | 12.7% | Nov 29, 2021 | The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the... |
| CVE-2021-44077 | CRITICAL | 9.8 | 93.5% | Nov 29, 2021 | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 ... |
| CVE-2021-44093 | CRITICAL | 9.8 | 2.5% | Nov 28, 2021 | A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass t... |
| CVE-2021-23654 | CRITICAL | 9.8 | 1.2% | Nov 26, 2021 | This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted with... |
| CVE-2021-26611 | CRITICAL | 9.8 | 1.1% | Nov 26, 2021 | HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to oper... |
| CVE-2021-38685 | CRITICAL | 9.8 | 1.5% | Nov 26, 2021 | A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability all... |
| CVE-2021-44223 | CRITICAL | 9.8 | 29.0% | Nov 25, 2021 | WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execut... |
| CVE-2021-44219 | CRITICAL | 9.8 | 1.3% | Nov 24, 2021 | Gin-Vue-Admin before 2.4.6 mishandles a SQL database. |
| CVE-2021-36916 | CRITICAL | 9.8 | 1.8% | Nov 24, 2021 | The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP... |
| CVE-2021-34423 | CRITICAL | 9.8 | 3.2% | Nov 24, 2021 | A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)... |
| CVE-2021-22049 | CRITICAL | 9.8 | 1.7% | Nov 24, 2021 | The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client ... |
| CVE-2021-3554 | CRITICAL | 10 | 2.7% | Nov 24, 2021 | Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for... |
| CVE-2021-20850 | CRITICAL | 9.8 | 1.5% | Nov 24, 2021 | PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 ... |
| CVE-2021-44140 | CRITICAL | 9.1 | 6.2% | Nov 24, 2021 | Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a... |
| CVE-2021-42785 | CRITICAL | 9.8 | 2.3% | Nov 23, 2021 | Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instruct... |
| CVE-2021-42784 | CRITICAL | 9.8 | 7.1% | Nov 23, 2021 | OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform comm... |
| CVE-2021-42783 | CRITICAL | 9.8 | 3.8% | Nov 23, 2021 | Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows a... |
| CVE-2021-38002 | CRITICAL | 9.6 | 0.9% | Nov 23, 2021 | Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform ... |
| CVE-2021-36314 | CRITICAL | 9.8 | 1.2% | Nov 23, 2021 | Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now