2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33672 | CRITICAL | 9.6 | 1.1% | Sep 14, 2021 | Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send mal... |
| CVE-2021-37184 | CRITICAL | 9.8 | 1.0% | Sep 14, 2021 | A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker cou... |
| CVE-2021-37181 | CRITICAL | 10 | 1.8% | Sep 14, 2021 | A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS ... |
| CVE-2021-33719 | CRITICAL | 9.8 | 2.1% | Sep 14, 2021 | A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 rela... |
| CVE-2021-31891 | CRITICAL | 10 | 3.8% | Sep 14, 2021 | A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions wit... |
| CVE-2021-27391 | CRITICAL | 9.8 | 3.3% | Sep 14, 2021 | A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Eth... |
| CVE-2021-38833 | CRITICAL | 9.8 | 2.2% | Sep 13, 2021 | SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute... |
| CVE-2021-3666 | CRITICAL | 9.8 | 1.3% | Sep 13, 2021 | body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution... |
| CVE-2021-33543 | CRITICAL | 9.8 | 82.1% | Sep 13, 2021 | Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive... |
| CVE-2021-24493 | CRITICAL | 9.8 | 1.9% | Sep 13, 2021 | The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authe... |
| CVE-2021-40870 | CRITICAL | 9.8 | 92.4% | Sep 13, 2021 | An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous ... |
| CVE-2021-23440 | CRITICAL | 9.8 | 2.3% | Sep 12, 2021 | This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of... |
| CVE-2021-40146 | CRITICAL | 9.8 | 5.5% | Sep 11, 2021 | A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect A... |
| CVE-2021-38555 | CRITICAL | 9.1 | 2.7% | Sep 11, 2021 | An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to a... |
| CVE-2021-24040 | CRITICAL | 9.8 | 17.4% | Sep 10, 2021 | Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files c... |
| CVE-2021-40864 | CRITICAL | 9.8 | 2.2% | Sep 10, 2021 | The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.d... |
| CVE-2021-37422 | CRITICAL | 9.8 | 3.3% | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. |
| CVE-2021-37423 | CRITICAL | 9.8 | 2.7% | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. |
| CVE-2021-40373 | CRITICAL | 9.8 | 4.7% | Sep 10, 2021 | playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_con... |
| CVE-2021-38360 | CRITICAL | 9.8 | 2.2% | Sep 10, 2021 | The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in... |
| CVE-2021-3645 | CRITICAL | 9.8 | 1.4% | Sep 10, 2021 | merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-34346 | CRITICAL | 9.8 | 1.5% | Sep 10, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploite... |
| CVE-2021-34345 | CRITICAL | 9.8 | 1.5% | Sep 10, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploite... |
| CVE-2021-34344 | CRITICAL | 9.8 | 1.5% | Sep 10, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulne... |
| CVE-2021-32724 | CRITICAL | 9.9 | 2.3% | Sep 9, 2021 | check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now