2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-33672CRITICAL9.6Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send mal...
CVE-2021-37184CRITICAL9.8A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker cou...
CVE-2021-37181CRITICAL10A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS ...
CVE-2021-33719CRITICAL9.8A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 rela...
CVE-2021-31891CRITICAL10A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions wit...
CVE-2021-27391CRITICAL9.8A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Eth...
CVE-2021-38833CRITICAL9.8SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute...
CVE-2021-3666CRITICAL9.8body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution...
CVE-2021-33543CRITICAL9.8Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive...
CVE-2021-24493CRITICAL9.8The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authe...
CVE-2021-40870CRITICAL9.8An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous ...
CVE-2021-23440CRITICAL9.8This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of...
CVE-2021-40146CRITICAL9.8A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect A...
CVE-2021-38555CRITICAL9.1An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to a...
CVE-2021-24040CRITICAL9.8Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files c...
CVE-2021-40864CRITICAL9.8The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.d...
CVE-2021-37422CRITICAL9.8Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
CVE-2021-37423CRITICAL9.8Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
CVE-2021-40373CRITICAL9.8playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_con...
CVE-2021-38360CRITICAL9.8The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in...
CVE-2021-3645CRITICAL9.8merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-34346CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploite...
CVE-2021-34345CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploite...
CVE-2021-34344CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulne...
CVE-2021-32724CRITICAL9.9check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now