2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-37761CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote cod...
CVE-2021-36880CRITICAL9.8Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable paramete...
CVE-2021-36879CRITICAL9.8Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPre...
CVE-2021-24666CRITICAL9.8The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by def...
CVE-2021-37539CRITICAL9.8Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
CVE-2021-36219CRITICAL9.8An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign...
CVE-2021-34416CRITICAL9.8The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360....
CVE-2021-33907CRITICAL9.8The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate informa...
CVE-2021-22272CRITICAL9.4The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number i...
CVE-2021-40098CRITICAL9.8An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regul...
CVE-2021-38299CRITICAL9.8Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to...
CVE-2021-34351CRITICAL9.8A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ...
CVE-2021-34348CRITICAL9.8A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ...
CVE-2021-22869CRITICAL9.8An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted ...
CVE-2021-40102CRITICAL9.1An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_...
CVE-2021-26794CRITICAL9.8Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php...
CVE-2021-21913CRITICAL9.8An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specia...
CVE-2021-32959CRITICAL9.8Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06
CVE-2021-22945CRITICAL9.1When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer...
CVE-2021-22941CRITICAL9.8Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke...
CVE-2021-22005CRITICAL9.8The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw...
CVE-2021-34770CRITICAL9.8A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE S...
CVE-2021-34727CRITICAL9.8A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker t...
CVE-2021-1619CRITICAL9.1A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow...
CVE-2021-40684CRITICAL9.1Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now