2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-21941CRITICAL9A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h....
CVE-2021-21940CRITICAL10A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase ...
CVE-2021-33725CRITICAL9.1A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delet...
CVE-2021-33724CRITICAL9.1A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arb...
CVE-2021-23448CRITICAL9.8All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.
CVE-2021-40617CRITICAL9.8An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
CVE-2021-40239CRITICAL9.8A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c
CVE-2021-41117CRITICAL9.1keypair is a a RSA PEM key generator written in javascript. keypair implements a lot of cryptographic primitives on its ...
CVE-2021-26588CRITICAL9.8A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 S...
CVE-2021-37123CRITICAL9.8There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when ...
CVE-2021-27664CRITICAL9.8Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVisi...
CVE-2021-40543CRITICAL9.8Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at ...
CVE-2021-40887CRITICAL9.8Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for ...
CVE-2021-40889CRITICAL9.8CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php fi...
CVE-2021-42139CRITICAL9.8Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
CVE-2021-37973CRITICAL9.6Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the rende...
CVE-2021-30633CRITICAL9.6Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised th...
CVE-2021-42109CRITICAL9.8VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
CVE-2021-41975CRITICAL9.1TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to del...
CVE-2021-41974CRITICAL9.1Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view a...
CVE-2021-41566CRITICAL9.8The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of f...
CVE-2021-36767CRITICAL9.8In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the serv...
CVE-2021-35977CRITICAL9.8An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP...
CVE-2021-38298CRITICAL9.8Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
CVE-2021-42091CRITICAL9.1An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now