2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-28254CRITICAL9.8A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary comma...
CVE-2021-40507CRITICAL9.8An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o...
CVE-2021-40506CRITICAL9.8An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o...
CVE-2021-33797CRITICAL9.8Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() rea...
CVE-2021-33990CRITICAL9.8Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The...
CVE-2021-46880CRITICAL9.8x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an ...
CVE-2021-31707CRITICAL9.8Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.
CVE-2021-28235CRITICAL9.8Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug func...
CVE-2021-45423CRITICAL9.8A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Name...
CVE-2021-33360CRITICAL9.8An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, pl...
CVE-2021-33353CRITICAL9.8Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows at...
CVE-2021-33352CRITICAL9.8An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitra...
CVE-2021-33351CRITICAL9Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allo...
CVE-2021-36394CRITICAL9.8In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CVE-2021-36393CRITICAL9.8In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
CVE-2021-36392CRITICAL9.8In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
CVE-2021-4329CRITICAL9.8A vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0. Affected by this issue is some...
CVE-2021-4328CRITICAL9.8A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function good...
CVE-2021-3854CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Us...
CVE-2021-4327CRITICAL9.8A vulnerability was found in SerenityOS. It has been rated as critical. Affected by this issue is the function initializ...
CVE-2021-35370CRITICAL9.8An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
CVE-2021-33387CRITICAL9.6Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request...
CVE-2021-33224CRITICAL9.8File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a craf...
CVE-2021-4105CRITICAL9.8Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affect...
CVE-2021-32853CRITICAL9.6Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.2...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now