2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-23438CRITICAL9.8This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In p...
CVE-2021-23436CRITICAL9.8This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when ...
CVE-2021-40350CRITICAL9.8webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafte...
CVE-2021-36020CRITICAL9.8Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Inj...
CVE-2021-23428CRITICAL9.8This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file p...
CVE-2021-23427CRITICAL9.8This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to ...
CVE-2021-39379CRITICAL9.8A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma...
CVE-2021-39378CRITICAL9.8A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma...
CVE-2021-39377CRITICAL9.8A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma...
CVE-2021-37415CRITICAL9.8Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs w...
CVE-2021-40353CRITICAL9.8A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database...
CVE-2021-22002CRITICAL9.8VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be a...
CVE-2021-22943CRITICAL9.6A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained ...
CVE-2021-21811CRITICAL9.8A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A...
CVE-2021-35222CRITICAL9.6This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Executio...
CVE-2021-34565CRITICAL9.8In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.
CVE-2021-38145CRITICAL9.8An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-p...
CVE-2021-36356CRITICAL9.8KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa...
CVE-2021-39177CRITICAL9.8Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNA...
CVE-2021-37421CRITICAL9.8Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
CVE-2021-37417CRITICAL9.8Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
CVE-2021-34646CRITICAL9.8Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication b...
CVE-2021-34066CRITICAL9.8An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability th...
CVE-2021-33055CRITICAL9.8Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
CVE-2021-38393CRITICAL9.8A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAE...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now