2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-37927CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
CVE-2021-37925CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
CVE-2021-36260CRITICAL9.8A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,...
CVE-2021-31819CRITICAL9.8In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on sy...
CVE-2021-23444CRITICAL9.8This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 whe...
CVE-2021-37424CRITICAL9.8ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
CVE-2021-28960CRITICAL9.8Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handlin...
CVE-2021-0869CRITICAL9.8In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. ...
CVE-2021-31917CRITICAL9.8A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An atta...
CVE-2021-40674CRITICAL9.8An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index....
CVE-2021-24741CRITICAL9.8The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, departmen...
CVE-2021-24638CRITICAL9.1The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows un...
CVE-2021-41393CRITICAL9.8Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificate...
CVE-2021-41392CRITICAL9.8static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafte...
CVE-2021-38412CRITICAL9.8Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Ra...
CVE-2021-41326CRITICAL9.8In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
CVE-2021-41317CRITICAL9.8XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
CVE-2021-39228CRITICAL9.8Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. Th...
CVE-2021-39227CRITICAL9.8ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge`...
CVE-2021-23442CRITICAL9.8This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.
CVE-2021-41303CRITICAL9.8Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authe...
CVE-2021-1976CRITICAL9.8A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snap...
CVE-2021-20791CRITICAL9.3Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restr...
CVE-2021-20790CRITICAL9.6Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execu...
CVE-2021-40670CRITICAL9.8SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now