2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37761 | CRITICAL | 9.8 | 9.2% | Sep 27, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote cod... |
| CVE-2021-36880 | CRITICAL | 9.8 | 2.1% | Sep 27, 2021 | Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable paramete... |
| CVE-2021-36879 | CRITICAL | 9.8 | 2.1% | Sep 27, 2021 | Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPre... |
| CVE-2021-24666 | CRITICAL | 9.8 | 9.4% | Sep 27, 2021 | The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by def... |
| CVE-2021-37539 | CRITICAL | 9.8 | 93.4% | Sep 27, 2021 | Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. |
| CVE-2021-36219 | CRITICAL | 9.8 | 1.6% | Sep 27, 2021 | An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign... |
| CVE-2021-34416 | CRITICAL | 9.8 | 1.6% | Sep 27, 2021 | The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.... |
| CVE-2021-33907 | CRITICAL | 9.8 | 3.0% | Sep 27, 2021 | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate informa... |
| CVE-2021-22272 | CRITICAL | 9.4 | 0.6% | Sep 27, 2021 | The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number i... |
| CVE-2021-40098 | CRITICAL | 9.8 | 1.6% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regul... |
| CVE-2021-38299 | CRITICAL | 9.8 | 1.7% | Sep 27, 2021 | Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to... |
| CVE-2021-34351 | CRITICAL | 9.8 | 1.5% | Sep 27, 2021 | A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ... |
| CVE-2021-34348 | CRITICAL | 9.8 | 1.5% | Sep 27, 2021 | A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ... |
| CVE-2021-22869 | CRITICAL | 9.8 | 1.2% | Sep 24, 2021 | An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted ... |
| CVE-2021-40102 | CRITICAL | 9.1 | 1.3% | Sep 24, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_... |
| CVE-2021-26794 | CRITICAL | 9.8 | 1.6% | Sep 23, 2021 | Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php... |
| CVE-2021-21913 | CRITICAL | 9.8 | 2.1% | Sep 23, 2021 | An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specia... |
| CVE-2021-32959 | CRITICAL | 9.8 | 0.9% | Sep 23, 2021 | Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06 |
| CVE-2021-22945 | CRITICAL | 9.1 | 6.2% | Sep 23, 2021 | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer... |
| CVE-2021-22941 | CRITICAL | 9.8 | 53.6% | Sep 23, 2021 | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke... |
| CVE-2021-22005 | CRITICAL | 9.8 | 100.0% | Sep 23, 2021 | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw... |
| CVE-2021-34770 | CRITICAL | 9.8 | 2.9% | Sep 23, 2021 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE S... |
| CVE-2021-34727 | CRITICAL | 9.8 | 2.5% | Sep 23, 2021 | A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker t... |
| CVE-2021-1619 | CRITICAL | 9.1 | 1.7% | Sep 23, 2021 | A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow... |
| CVE-2021-40684 | CRITICAL | 9.1 | 1.1% | Sep 22, 2021 | Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now