2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-3769CRITICAL9.8# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P`...
CVE-2021-3727CRITICAL9.8# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes fro...
CVE-2021-3726CRITICAL9.8# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` ...
CVE-2021-44427CRITICAL9.8An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow...
CVE-2021-43691CRITICAL9.8tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The varia...
CVE-2021-43693CRITICAL9.8vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
CVE-2021-24915CRITICAL9.8The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the...
CVE-2021-44077CRITICAL9.8Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 ...
CVE-2021-44093CRITICAL9.8A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass t...
CVE-2021-23654CRITICAL9.8This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted with...
CVE-2021-26611CRITICAL9.8HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to oper...
CVE-2021-38685CRITICAL9.8A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability all...
CVE-2021-44223CRITICAL9.8WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execut...
CVE-2021-44219CRITICAL9.8Gin-Vue-Admin before 2.4.6 mishandles a SQL database.
CVE-2021-36916CRITICAL9.8The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP...
CVE-2021-34423CRITICAL9.8A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)...
CVE-2021-22049CRITICAL9.8The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client ...
CVE-2021-3554CRITICAL10Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for...
CVE-2021-20850CRITICAL9.8PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 ...
CVE-2021-44140CRITICAL9.1Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a...
CVE-2021-42785CRITICAL9.8Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instruct...
CVE-2021-42784CRITICAL9.8OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform comm...
CVE-2021-42783CRITICAL9.8Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows a...
CVE-2021-38002CRITICAL9.6Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform ...
CVE-2021-36314CRITICAL9.8Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now