2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32234 | CRITICAL | 9.8 | 2.1% | Nov 17, 2021 | SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution. |
| CVE-2021-41931 | CRITICAL | 9.8 | 1.3% | Nov 17, 2021 | The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnera... |
| CVE-2021-43048 | CRITICAL | 9.8 | 1.2% | Nov 16, 2021 | The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability ... |
| CVE-2021-43047 | CRITICAL | 9 | 1.0% | Nov 16, 2021 | The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain easily exploitab... |
| CVE-2021-43362 | CRITICAL | 9.8 | 0.6% | Nov 16, 2021 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allow... |
| CVE-2021-43361 | CRITICAL | 9.8 | 0.6% | Nov 16, 2021 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allow... |
| CVE-2021-3958 | CRITICAL | 9.8 | 14.5% | Nov 16, 2021 | Improper Handling of Parameters vulnerability in Ipack Automation Systems Ipack SCADA Software allows : Blind SQL Inject... |
| CVE-2021-37580 | CRITICAL | 9.8 | 40.1% | Nov 16, 2021 | A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass a... |
| CVE-2021-25985 | CRITICAL | 9.8 | 0.8% | Nov 16, 2021 | In Factor (App Framework & Headless CMS) v1.0.4 to v1.8.30, improperly invalidate a user’s session even after the user l... |
| CVE-2021-42377 | CRITICAL | 9.8 | 3.4% | Nov 15, 2021 | An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when... |
| CVE-2021-41269 | CRITICAL | 9.8 | 4.0% | Nov 15, 2021 | cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for th... |
| CVE-2021-41266 | CRITICAL | 9.8 | 51.4% | Nov 15, 2021 | Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage pro... |
| CVE-2021-42580 | CRITICAL | 9.8 | 10.0% | Nov 15, 2021 | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm... |
| CVE-2021-41950 | CRITICAL | 9.1 | 74.9% | Nov 15, 2021 | A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete ... |
| CVE-2021-41765 | CRITICAL | 9.8 | 67.8% | Nov 15, 2021 | A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote... |
| CVE-2021-43272 | CRITICAL | 9.8 | 3.5% | Nov 14, 2021 | An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 202... |
| CVE-2021-43617 | CRITICAL | 9.8 | 19.8% | Nov 14, 2021 | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val... |
| CVE-2021-43616 | CRITICAL | 9.8 | 2.5% | Nov 13, 2021 | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack... |
| CVE-2021-41653 | CRITICAL | 9.8 | 77.5% | Nov 13, 2021 | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to r... |
| CVE-2021-3918 | CRITICAL | 9.8 | 3.6% | Nov 13, 2021 | json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-38684 | CRITICAL | 9.8 | 1.3% | Nov 13, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, thi... |
| CVE-2021-39303 | CRITICAL | 9.8 | 1.7% | Nov 12, 2021 | The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an a... |
| CVE-2021-41264 | CRITICAL | 9.8 | 1.4% | Nov 12, 2021 | OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UU... |
| CVE-2021-30321 | CRITICAL | 9.8 | 0.8% | Nov 12, 2021 | Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Compute, Snapdr... |
| CVE-2021-30284 | CRITICAL | 9.1 | 0.6% | Nov 12, 2021 | Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapd... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now