2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21941 | CRITICAL | 9 | 1.6% | Oct 12, 2021 | A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h.... |
| CVE-2021-21940 | CRITICAL | 10 | 1.3% | Oct 12, 2021 | A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase ... |
| CVE-2021-33725 | CRITICAL | 9.1 | 1.0% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delet... |
| CVE-2021-33724 | CRITICAL | 9.1 | 1.0% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arb... |
| CVE-2021-23448 | CRITICAL | 9.8 | 1.2% | Oct 11, 2021 | All versions of package config-handler are vulnerable to Prototype Pollution when loading config files. |
| CVE-2021-40617 | CRITICAL | 9.8 | 5.2% | Oct 11, 2021 | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. |
| CVE-2021-40239 | CRITICAL | 9.8 | 1.4% | Oct 11, 2021 | A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c |
| CVE-2021-41117 | CRITICAL | 9.1 | 3.0% | Oct 11, 2021 | keypair is a a RSA PEM key generator written in javascript. keypair implements a lot of cryptographic primitives on its ... |
| CVE-2021-26588 | CRITICAL | 9.8 | 1.8% | Oct 11, 2021 | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 S... |
| CVE-2021-37123 | CRITICAL | 9.8 | 0.8% | Oct 11, 2021 | There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when ... |
| CVE-2021-27664 | CRITICAL | 9.8 | 1.5% | Oct 11, 2021 | Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVisi... |
| CVE-2021-40543 | CRITICAL | 9.8 | 1.1% | Oct 11, 2021 | Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at ... |
| CVE-2021-40887 | CRITICAL | 9.8 | 2.3% | Oct 11, 2021 | Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for ... |
| CVE-2021-40889 | CRITICAL | 9.8 | 1.8% | Oct 11, 2021 | CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php fi... |
| CVE-2021-42139 | CRITICAL | 9.8 | 2.0% | Oct 11, 2021 | Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. |
| CVE-2021-37973 | CRITICAL | 9.6 | 11.7% | Oct 8, 2021 | Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the rende... |
| CVE-2021-30633 | CRITICAL | 9.6 | 32.7% | Oct 8, 2021 | Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised th... |
| CVE-2021-42109 | CRITICAL | 9.8 | 1.6% | Oct 8, 2021 | VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root. |
| CVE-2021-41975 | CRITICAL | 9.1 | 1.3% | Oct 8, 2021 | TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to del... |
| CVE-2021-41974 | CRITICAL | 9.1 | 1.2% | Oct 8, 2021 | Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view a... |
| CVE-2021-41566 | CRITICAL | 9.8 | 1.9% | Oct 8, 2021 | The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of f... |
| CVE-2021-36767 | CRITICAL | 9.8 | 0.7% | Oct 8, 2021 | In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the serv... |
| CVE-2021-35977 | CRITICAL | 9.8 | 1.5% | Oct 8, 2021 | An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP... |
| CVE-2021-38298 | CRITICAL | 9.8 | 2.5% | Oct 7, 2021 | Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE. |
| CVE-2021-42091 | CRITICAL | 9.1 | 1.0% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now