2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-38391CRITICAL9.8A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnerg...
CVE-2021-38390CRITICAL9.8A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAE...
CVE-2021-32983CRITICAL9.8A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie...
CVE-2021-32967CRITICAL9.8Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without bein...
CVE-2021-32955CRITICAL9.8Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to re...
CVE-2021-27663CRITICAL9.8A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access ...
CVE-2021-21741CRITICAL9.8There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by defaul...
CVE-2021-26084CRITICAL9.8In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un...
CVE-2021-37749CRITICAL9.8MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (wi...
CVE-2021-40177CRITICAL9.8Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
CVE-2021-40175CRITICAL9.8Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
CVE-2021-39168CRITICAL9.8OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allo...
CVE-2021-39167CRITICAL9.8OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allo...
CVE-2021-29772CRITICAL9.8IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IB...
CVE-2021-29715CRITICAL9.1IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of...
CVE-2021-32648CRITICAL9.1octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an a...
CVE-2021-40147CRITICAL9.8EmTec ZOC before 8.02.2 allows \e[201~ pastes, a different vulnerability than CVE-2021-32198.
CVE-2021-27944CRITICAL9.8Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access cont...
CVE-2021-37334CRITICAL9.8Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a r...
CVE-2021-37154CRITICAL9.8In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a ...
CVE-2021-37153CRITICAL9.8ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authe...
CVE-2021-1581CRITICAL9.1Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or...
CVE-2021-1577CRITICAL9.1A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Applicat...
CVE-2021-39159CRITICAL9.8BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments...
CVE-2021-33885CRITICAL9.8An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remot...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now