2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23438 | CRITICAL | 9.8 | 1.7% | Sep 1, 2021 | This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In p... |
| CVE-2021-23436 | CRITICAL | 9.8 | 1.8% | Sep 1, 2021 | This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when ... |
| CVE-2021-40350 | CRITICAL | 9.8 | 1.6% | Sep 1, 2021 | webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafte... |
| CVE-2021-36020 | CRITICAL | 9.8 | 2.7% | Sep 1, 2021 | Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Inj... |
| CVE-2021-23428 | CRITICAL | 9.8 | 1.7% | Sep 1, 2021 | This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file p... |
| CVE-2021-23427 | CRITICAL | 9.8 | 1.4% | Sep 1, 2021 | This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to ... |
| CVE-2021-39379 | CRITICAL | 9.8 | 3.6% | Sep 1, 2021 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma... |
| CVE-2021-39378 | CRITICAL | 9.8 | 22.7% | Sep 1, 2021 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma... |
| CVE-2021-39377 | CRITICAL | 9.8 | 3.6% | Sep 1, 2021 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma... |
| CVE-2021-37415 | CRITICAL | 9.8 | 99.9% | Sep 1, 2021 | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs w... |
| CVE-2021-40353 | CRITICAL | 9.8 | 2.9% | Sep 1, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database... |
| CVE-2021-22002 | CRITICAL | 9.8 | 1.2% | Aug 31, 2021 | VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be a... |
| CVE-2021-22943 | CRITICAL | 9.6 | 0.4% | Aug 31, 2021 | A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained ... |
| CVE-2021-21811 | CRITICAL | 9.8 | 1.1% | Aug 31, 2021 | A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A... |
| CVE-2021-35222 | CRITICAL | 9.6 | 2.6% | Aug 31, 2021 | This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Executio... |
| CVE-2021-34565 | CRITICAL | 9.8 | 1.0% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. |
| CVE-2021-38145 | CRITICAL | 9.8 | 2.2% | Aug 31, 2021 | An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-p... |
| CVE-2021-36356 | CRITICAL | 9.8 | 54.4% | Aug 31, 2021 | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa... |
| CVE-2021-39177 | CRITICAL | 9.8 | 1.4% | Aug 30, 2021 | Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNA... |
| CVE-2021-37421 | CRITICAL | 9.8 | 2.5% | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. |
| CVE-2021-37417 | CRITICAL | 9.8 | 4.8% | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. |
| CVE-2021-34646 | CRITICAL | 9.8 | 50.9% | Aug 30, 2021 | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication b... |
| CVE-2021-34066 | CRITICAL | 9.8 | 2.0% | Aug 30, 2021 | An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability th... |
| CVE-2021-33055 | CRITICAL | 9.8 | 18.1% | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions. |
| CVE-2021-38393 | CRITICAL | 9.8 | 19.9% | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAE... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now