2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-24019CRITICAL9.8An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below ...
CVE-2021-3625CRITICAL9.8Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For mo...
CVE-2021-3319CRITICAL9.8DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses. Zephyr versions >= > v2.4.0 contain NULL Poi...
CVE-2021-41116CRITICAL9.8Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer ...
CVE-2021-41553CRITICAL9.8In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session t...
CVE-2021-41773CRITICAL9.8A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path trave...
CVE-2021-41100CRITICAL9.8Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is poss...
CVE-2021-41093CRITICAL9.8Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they...
CVE-2021-23857CRITICAL9.8Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the...
CVE-2021-41592CRITICAL9.4Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.
CVE-2021-41591CRITICAL9.4ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.
CVE-2021-35296CRITICAL9.8An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via m...
CVE-2021-41868CRITICAL9.8OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --...
CVE-2021-38823CRITICAL9.8The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not ...
CVE-2021-37333CRITICAL9.8Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.or...
CVE-2021-41511CRITICAL9.8The username and password field of login in Lodging Reservation Management System V1 can give access to any user by usin...
CVE-2021-40323CRITICAL9.8Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo...
CVE-2021-41862CRITICAL9.8AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (...
CVE-2021-36298CRITICAL9.8Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component. A remote unaut...
CVE-2021-41647CRITICAL9.1An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Or...
CVE-2021-3825CRITICAL9.6On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. ...
CVE-2021-41649CRITICAL9.8An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php c...
CVE-2021-40960CRITICAL9.8Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd...
CVE-2021-41110CRITICAL9.8cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a D...
CVE-2021-34352CRITICAL9.8A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now