2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37927 | CRITICAL | 9.8 | 2.2% | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. |
| CVE-2021-37925 | CRITICAL | 9.8 | 10.5% | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability. |
| CVE-2021-36260 | CRITICAL | 9.8 | 99.9% | Sep 22, 2021 | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,... |
| CVE-2021-31819 | CRITICAL | 9.8 | 2.3% | Sep 22, 2021 | In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on sy... |
| CVE-2021-23444 | CRITICAL | 9.8 | 1.8% | Sep 21, 2021 | This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 whe... |
| CVE-2021-37424 | CRITICAL | 9.8 | 4.6% | Sep 21, 2021 | ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. |
| CVE-2021-28960 | CRITICAL | 9.8 | 2.0% | Sep 21, 2021 | Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handlin... |
| CVE-2021-0869 | CRITICAL | 9.8 | 0.8% | Sep 21, 2021 | In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. ... |
| CVE-2021-31917 | CRITICAL | 9.8 | 1.3% | Sep 21, 2021 | A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An atta... |
| CVE-2021-40674 | CRITICAL | 9.8 | 1.1% | Sep 20, 2021 | An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.... |
| CVE-2021-24741 | CRITICAL | 9.8 | 5.5% | Sep 20, 2021 | The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, departmen... |
| CVE-2021-24638 | CRITICAL | 9.1 | 1.8% | Sep 20, 2021 | The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows un... |
| CVE-2021-41393 | CRITICAL | 9.8 | 1.0% | Sep 18, 2021 | Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificate... |
| CVE-2021-41392 | CRITICAL | 9.8 | 2.7% | Sep 17, 2021 | static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafte... |
| CVE-2021-38412 | CRITICAL | 9.8 | 1.3% | Sep 17, 2021 | Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Ra... |
| CVE-2021-41326 | CRITICAL | 9.8 | 2.0% | Sep 17, 2021 | In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call. |
| CVE-2021-41317 | CRITICAL | 9.8 | 1.7% | Sep 17, 2021 | XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths. |
| CVE-2021-39228 | CRITICAL | 9.8 | 1.3% | Sep 17, 2021 | Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. Th... |
| CVE-2021-39227 | CRITICAL | 9.8 | 1.3% | Sep 17, 2021 | ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge`... |
| CVE-2021-23442 | CRITICAL | 9.8 | 1.5% | Sep 17, 2021 | This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object. |
| CVE-2021-41303 | CRITICAL | 9.8 | 75.6% | Sep 17, 2021 | Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authe... |
| CVE-2021-1976 | CRITICAL | 9.8 | 0.8% | Sep 17, 2021 | A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snap... |
| CVE-2021-20791 | CRITICAL | 9.3 | 0.8% | Sep 17, 2021 | Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restr... |
| CVE-2021-20790 | CRITICAL | 9.6 | 1.2% | Sep 17, 2021 | Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execu... |
| CVE-2021-40670 | CRITICAL | 9.8 | 1.2% | Sep 16, 2021 | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now