2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28254 | CRITICAL | 9.8 | 1.3% | Apr 19, 2023 | A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary comma... |
| CVE-2021-40507 | CRITICAL | 9.8 | 0.7% | Apr 18, 2023 | An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o... |
| CVE-2021-40506 | CRITICAL | 9.8 | 0.7% | Apr 18, 2023 | An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o... |
| CVE-2021-33797 | CRITICAL | 9.8 | 0.8% | Apr 17, 2023 | Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() rea... |
| CVE-2021-33990 | CRITICAL | 9.8 | 11.9% | Apr 16, 2023 | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The... |
| CVE-2021-46880 | CRITICAL | 9.8 | 0.6% | Apr 15, 2023 | x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an ... |
| CVE-2021-31707 | CRITICAL | 9.8 | 1.3% | Apr 4, 2023 | Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type. |
| CVE-2021-28235 | CRITICAL | 9.8 | 1.6% | Apr 4, 2023 | Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug func... |
| CVE-2021-45423 | CRITICAL | 9.8 | 1.1% | Mar 13, 2023 | A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Name... |
| CVE-2021-33360 | CRITICAL | 9.8 | 1.1% | Mar 10, 2023 | An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, pl... |
| CVE-2021-33353 | CRITICAL | 9.8 | 2.2% | Mar 8, 2023 | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows at... |
| CVE-2021-33352 | CRITICAL | 9.8 | 1.4% | Mar 8, 2023 | An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitra... |
| CVE-2021-33351 | CRITICAL | 9 | 1.0% | Mar 8, 2023 | Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allo... |
| CVE-2021-36394 | CRITICAL | 9.8 | 7.0% | Mar 6, 2023 | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. |
| CVE-2021-36393 | CRITICAL | 9.8 | 52.3% | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. |
| CVE-2021-36392 | CRITICAL | 9.8 | 0.8% | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. |
| CVE-2021-4329 | CRITICAL | 9.8 | 2.3% | Mar 5, 2023 | A vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0. Affected by this issue is some... |
| CVE-2021-4328 | CRITICAL | 9.8 | 0.7% | Mar 2, 2023 | A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function good... |
| CVE-2021-3854 | CRITICAL | 9.8 | 0.6% | Mar 2, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Us... |
| CVE-2021-4327 | CRITICAL | 9.8 | 0.9% | Mar 1, 2023 | A vulnerability was found in SerenityOS. It has been rated as critical. Affected by this issue is the function initializ... |
| CVE-2021-35370 | CRITICAL | 9.8 | 1.0% | Feb 24, 2023 | An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function. |
| CVE-2021-33387 | CRITICAL | 9.6 | 0.8% | Feb 24, 2023 | Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request... |
| CVE-2021-33224 | CRITICAL | 9.8 | 0.7% | Feb 24, 2023 | File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a craf... |
| CVE-2021-4105 | CRITICAL | 9.8 | 0.9% | Feb 24, 2023 | Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affect... |
| CVE-2021-32853 | CRITICAL | 9.6 | 3.1% | Feb 20, 2023 | Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.2... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now