2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40669 | CRITICAL | 9.8 | 1.2% | Sep 16, 2021 | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/i... |
| CVE-2021-40438 | CRITICAL | 9 | 100.0% | Sep 16, 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. Th... |
| CVE-2021-39275 | CRITICAL | 9.8 | 36.3% | Sep 16, 2021 | ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted d... |
| CVE-2021-39214 | CRITICAL | 9.8 | 1.1% | Sep 16, 2021 | mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or ser... |
| CVE-2021-27341 | CRITICAL | 9.8 | 2.0% | Sep 16, 2021 | OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via t... |
| CVE-2021-40881 | CRITICAL | 9.8 | 1.6% | Sep 15, 2021 | An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code. |
| CVE-2021-33045 | CRITICAL | 9.8 | 99.6% | Sep 15, 2021 | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by... |
| CVE-2021-33044 | CRITICAL | 9.8 | 99.9% | Sep 15, 2021 | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by... |
| CVE-2021-37913 | CRITICAL | 9.8 | 2.8% | Sep 15, 2021 | The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interfa... |
| CVE-2021-37912 | CRITICAL | 9.8 | 2.8% | Sep 15, 2021 | The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network inte... |
| CVE-2021-37909 | CRITICAL | 9.8 | 1.9% | Sep 15, 2021 | WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite t... |
| CVE-2021-33701 | CRITICAL | 9.1 | 2.0% | Sep 15, 2021 | DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 201... |
| CVE-2021-33695 | CRITICAL | 9.1 | 0.5% | Sep 15, 2021 | Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation... |
| CVE-2021-33690 | CRITICAL | 9.9 | 67.7% | Sep 15, 2021 | Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo... |
| CVE-2021-39392 | CRITICAL | 9.8 | 2.2% | Sep 15, 2021 | The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because ... |
| CVE-2021-3797 | CRITICAL | 9.8 | 1.1% | Sep 15, 2021 | hestiacp is vulnerable to Use of Wrong Operator in String Comparison |
| CVE-2021-38647 | CRITICAL | 9.8 | 99.7% | Sep 15, 2021 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
| CVE-2021-3751 | CRITICAL | 9.8 | 1.2% | Sep 15, 2021 | libmobi is vulnerable to Out-of-bounds Write |
| CVE-2021-23031 | CRITICAL | 9.9 | 2.0% | Sep 14, 2021 | On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.... |
| CVE-2021-23038 | CRITICAL | 9 | 0.9% | Sep 14, 2021 | On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versi... |
| CVE-2021-23037 | CRITICAL | 9.6 | 0.8% | Sep 14, 2021 | On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vu... |
| CVE-2021-38162 | CRITICAL | 9.4 | 2.6% | Sep 14, 2021 | SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.... |
| CVE-2021-37535 | CRITICAL | 9.8 | 1.2% | Sep 14, 2021 | SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not pe... |
| CVE-2021-36582 | CRITICAL | 9.8 | 1.5% | Sep 14, 2021 | In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to recei... |
| CVE-2021-36581 | CRITICAL | 9.8 | 1.5% | Sep 14, 2021 | Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now