2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-43568CRITICAL9.8The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non...
CVE-2021-43200CRITICAL9.8In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
CVE-2021-43193CRITICAL9.8In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
CVE-2021-43185CRITICAL9.8JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
CVE-2021-43183CRITICAL9.8In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
CVE-2021-43466CRITICAL9.8In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to ...
CVE-2021-40358CRITICAL9.9A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC...
CVE-2021-31890CRITICAL9.1A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R...
CVE-2021-31889CRITICAL9.1A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R...
CVE-2021-31886CRITICAL9.8A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver...
CVE-2021-31884CRITICAL9.8A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver...
CVE-2021-31346CRITICAL9.1A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R...
CVE-2021-31345CRITICAL9.1A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R...
CVE-2021-41170CRITICAL9.8neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures d...
CVE-2021-24827CRITICAL9.8The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic be...
CVE-2021-24731CRITICAL9.8The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres...
CVE-2021-24693CRITICAL9The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputti...
CVE-2021-28024CRITICAL9.8Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to lo...
CVE-2021-28023CRITICAL9.8Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious...
CVE-2021-25979CRITICAL9.8Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or chang...
CVE-2021-30132CRITICAL9.8Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
CVE-2021-42371CRITICAL9.8lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.
CVE-2021-42077CRITICAL9.8PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username...
CVE-2021-34684CRITICAL9.8Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries o...
CVE-2021-42359CRITICAL9.1WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a n...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now