2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-40669CRITICAL9.8SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/i...
CVE-2021-40438CRITICAL9A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. Th...
CVE-2021-39275CRITICAL9.8ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted d...
CVE-2021-39214CRITICAL9.8mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or ser...
CVE-2021-27341CRITICAL9.8OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via t...
CVE-2021-40881CRITICAL9.8An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
CVE-2021-33045CRITICAL9.8The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by...
CVE-2021-33044CRITICAL9.8The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by...
CVE-2021-37913CRITICAL9.8The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interfa...
CVE-2021-37912CRITICAL9.8The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network inte...
CVE-2021-37909CRITICAL9.8WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite t...
CVE-2021-33701CRITICAL9.1DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 201...
CVE-2021-33695CRITICAL9.1Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation...
CVE-2021-33690CRITICAL9.9Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo...
CVE-2021-39392CRITICAL9.8The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because ...
CVE-2021-3797CRITICAL9.8hestiacp is vulnerable to Use of Wrong Operator in String Comparison
CVE-2021-38647CRITICAL9.8Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2021-3751CRITICAL9.8libmobi is vulnerable to Out-of-bounds Write
CVE-2021-23031CRITICAL9.9On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12....
CVE-2021-23038CRITICAL9On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versi...
CVE-2021-23037CRITICAL9.6On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vu...
CVE-2021-38162CRITICAL9.4SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7....
CVE-2021-37535CRITICAL9.8SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not pe...
CVE-2021-36582CRITICAL9.8In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to recei...
CVE-2021-36581CRITICAL9.8Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now