2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-32852CRITICAL9Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edi...
CVE-2021-26277CRITICAL9.8The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to per...
CVE-2021-35261CRITICAL9.8File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker t...
CVE-2021-34182CRITICAL9.8An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
CVE-2021-33949CRITICAL9.8An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function...
CVE-2021-33948CRITICAL9.8SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the usernam...
CVE-2021-33391CRITICAL9.8An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() funct...
CVE-2021-33226CRITICAL9.8Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func vari...
CVE-2021-32163CRITICAL9.8Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorizatio...
CVE-2021-43529CRITICAL9.8Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/M...
CVE-2021-42761CRITICAL9.8A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions...
CVE-2021-42756CRITICAL9.8Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 a...
CVE-2021-33925CRITICAL9.8SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May ...
CVE-2021-33304CRITICAL9.8Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pi...
CVE-2021-36471CRITICAL9.8Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensiti...
CVE-2021-31578CRITICAL9.8In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation...
CVE-2021-31577CRITICAL9.8In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalat...
CVE-2021-31575CRITICAL9.8In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2021-31574CRITICAL9.8In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2021-31573CRITICAL9.8In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2021-36226CRITICAL9.8Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
CVE-2021-36224CRITICAL9.8Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
CVE-2021-37497CRITICAL9.8SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted...
CVE-2021-37317CRITICAL9.1Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows...
CVE-2021-37315CRITICAL9.1Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now