2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20837 | CRITICAL | 9.8 | 88.1% | Oct 26, 2021 | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab... |
| CVE-2021-41035 | CRITICAL | 9.8 | 1.7% | Oct 25, 2021 | In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inacces... |
| CVE-2021-24884 | CRITICAL | 9.6 | 3.1% | Oct 25, 2021 | The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img... |
| CVE-2021-40865 | CRITICAL | 9.8 | 65.6% | Oct 25, 2021 | An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre... |
| CVE-2021-38294 | CRITICAL | 9.8 | 84.5% | Oct 25, 2021 | A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Ap... |
| CVE-2021-40371 | CRITICAL | 9.8 | 6.9% | Oct 25, 2021 | Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, ... |
| CVE-2021-42258 | CRITICAL | 9.8 | 73.3% | Oct 22, 2021 | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution... |
| CVE-2021-42169 | CRITICAL | 9.8 | 2.7% | Oct 22, 2021 | The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable f... |
| CVE-2021-41745 | CRITICAL | 9.8 | 1.3% | Oct 22, 2021 | ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. |
| CVE-2021-41744 | CRITICAL | 9.8 | 1.5% | Oct 22, 2021 | All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a st... |
| CVE-2021-38481 | CRITICAL | 9.8 | 0.9% | Oct 22, 2021 | The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of ... |
| CVE-2021-38477 | CRITICAL | 9.8 | 1.1% | Oct 22, 2021 | There are multiple API function codes that permit reading and writing data to or from files and directories, which could... |
| CVE-2021-38471 | CRITICAL | 9.1 | 1.0% | Oct 22, 2021 | There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existi... |
| CVE-2021-38459 | CRITICAL | 9.8 | 1.0% | Oct 22, 2021 | The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specifi... |
| CVE-2021-38457 | CRITICAL | 9.8 | 1.3% | Oct 22, 2021 | The server permits communication without any authentication procedure, allowing the attacker to initiate a session with ... |
| CVE-2021-38453 | CRITICAL | 9.1 | 1.0% | Oct 22, 2021 | Some API functions allow interaction with the registry, which includes reading values as well as data modification. |
| CVE-2021-38449 | CRITICAL | 9.8 | 1.2% | Oct 22, 2021 | Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these paramet... |
| CVE-2021-36357 | CRITICAL | 9.8 | 1.1% | Oct 22, 2021 | An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uin... |
| CVE-2021-40719 | CRITICAL | 9.8 | 3.4% | Oct 21, 2021 | Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve a... |
| CVE-2021-42740 | CRITICAL | 9.8 | 4.3% | Oct 21, 2021 | The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metach... |
| CVE-2021-41163 | CRITICAL | 9.8 | 19.8% | Oct 20, 2021 | Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could l... |
| CVE-2021-42766 | CRITICAL | 9.1 | 0.9% | Oct 20, 2021 | The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service... |
| CVE-2021-42764 | CRITICAL | 9.1 | 0.9% | Oct 20, 2021 | The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service... |
| CVE-2021-21749 | CRITICAL | 9.8 | 1.6% | Oct 20, 2021 | ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to... |
| CVE-2021-21748 | CRITICAL | 9.8 | 1.7% | Oct 20, 2021 | ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now