2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-20837CRITICAL9.8Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab...
CVE-2021-41035CRITICAL9.8In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inacces...
CVE-2021-24884CRITICAL9.6The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img...
CVE-2021-40865CRITICAL9.8An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre...
CVE-2021-38294CRITICAL9.8A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Ap...
CVE-2021-40371CRITICAL9.8Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, ...
CVE-2021-42258CRITICAL9.8BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution...
CVE-2021-42169CRITICAL9.8The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable f...
CVE-2021-41745CRITICAL9.8ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
CVE-2021-41744CRITICAL9.8All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a st...
CVE-2021-38481CRITICAL9.8The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of ...
CVE-2021-38477CRITICAL9.8There are multiple API function codes that permit reading and writing data to or from files and directories, which could...
CVE-2021-38471CRITICAL9.1There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existi...
CVE-2021-38459CRITICAL9.8The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specifi...
CVE-2021-38457CRITICAL9.8The server permits communication without any authentication procedure, allowing the attacker to initiate a session with ...
CVE-2021-38453CRITICAL9.1Some API functions allow interaction with the registry, which includes reading values as well as data modification.
CVE-2021-38449CRITICAL9.8Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these paramet...
CVE-2021-36357CRITICAL9.8An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uin...
CVE-2021-40719CRITICAL9.8Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve a...
CVE-2021-42740CRITICAL9.8The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metach...
CVE-2021-41163CRITICAL9.8Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could l...
CVE-2021-42766CRITICAL9.1The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service...
CVE-2021-42764CRITICAL9.1The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service...
CVE-2021-21749CRITICAL9.8ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to...
CVE-2021-21748CRITICAL9.8ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now