2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32852 | CRITICAL | 9 | 0.9% | Feb 20, 2023 | Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edi... |
| CVE-2021-26277 | CRITICAL | 9.8 | 0.3% | Feb 17, 2023 | The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to per... |
| CVE-2021-35261 | CRITICAL | 9.8 | 0.8% | Feb 17, 2023 | File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker t... |
| CVE-2021-34182 | CRITICAL | 9.8 | 0.9% | Feb 17, 2023 | An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions. |
| CVE-2021-33949 | CRITICAL | 9.8 | 1.0% | Feb 17, 2023 | An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function... |
| CVE-2021-33948 | CRITICAL | 9.8 | 0.8% | Feb 17, 2023 | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the usernam... |
| CVE-2021-33391 | CRITICAL | 9.8 | 1.1% | Feb 17, 2023 | An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() funct... |
| CVE-2021-33226 | CRITICAL | 9.8 | 1.6% | Feb 17, 2023 | Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func vari... |
| CVE-2021-32163 | CRITICAL | 9.8 | 0.9% | Feb 17, 2023 | Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorizatio... |
| CVE-2021-43529 | CRITICAL | 9.8 | 0.5% | Feb 16, 2023 | Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/M... |
| CVE-2021-42761 | CRITICAL | 9.8 | 1.5% | Feb 16, 2023 | A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions... |
| CVE-2021-42756 | CRITICAL | 9.8 | 36.4% | Feb 16, 2023 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 a... |
| CVE-2021-33925 | CRITICAL | 9.8 | 1.0% | Feb 15, 2023 | SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May ... |
| CVE-2021-33304 | CRITICAL | 9.8 | 0.8% | Feb 15, 2023 | Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pi... |
| CVE-2021-36471 | CRITICAL | 9.8 | 1.7% | Feb 7, 2023 | Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensiti... |
| CVE-2021-31578 | CRITICAL | 9.8 | 1.3% | Feb 6, 2023 | In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation... |
| CVE-2021-31577 | CRITICAL | 9.8 | 1.1% | Feb 6, 2023 | In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalat... |
| CVE-2021-31575 | CRITICAL | 9.8 | 1.7% | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2021-31574 | CRITICAL | 9.8 | 1.7% | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2021-31573 | CRITICAL | 9.8 | 1.7% | Feb 6, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2021-36226 | CRITICAL | 9.8 | 0.8% | Feb 6, 2023 | Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files. |
| CVE-2021-36224 | CRITICAL | 9.8 | 1.2% | Feb 6, 2023 | Western Digital My Cloud devices before OS5 have a nobody account with a blank password. |
| CVE-2021-37497 | CRITICAL | 9.8 | 1.3% | Feb 3, 2023 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted... |
| CVE-2021-37317 | CRITICAL | 9.1 | 1.5% | Feb 3, 2023 | Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows... |
| CVE-2021-37315 | CRITICAL | 9.1 | 1.1% | Feb 3, 2023 | Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now