2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38391 | CRITICAL | 9.8 | 3.5% | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnerg... |
| CVE-2021-38390 | CRITICAL | 9.8 | 19.8% | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAE... |
| CVE-2021-32983 | CRITICAL | 9.8 | 3.9% | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie... |
| CVE-2021-32967 | CRITICAL | 9.8 | 1.4% | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without bein... |
| CVE-2021-32955 | CRITICAL | 9.8 | 37.3% | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to re... |
| CVE-2021-27663 | CRITICAL | 9.8 | 1.7% | Aug 30, 2021 | A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access ... |
| CVE-2021-21741 | CRITICAL | 9.8 | 1.9% | Aug 30, 2021 | There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by defaul... |
| CVE-2021-26084 | CRITICAL | 9.8 | 100.0% | Aug 30, 2021 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un... |
| CVE-2021-37749 | CRITICAL | 9.8 | 1.8% | Aug 30, 2021 | MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (wi... |
| CVE-2021-40177 | CRITICAL | 9.8 | 4.6% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite. |
| CVE-2021-40175 | CRITICAL | 9.8 | 7.0% | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. |
| CVE-2021-39168 | CRITICAL | 9.8 | 1.6% | Aug 27, 2021 | OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allo... |
| CVE-2021-39167 | CRITICAL | 9.8 | 1.6% | Aug 27, 2021 | OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allo... |
| CVE-2021-29772 | CRITICAL | 9.8 | 0.9% | Aug 26, 2021 | IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IB... |
| CVE-2021-29715 | CRITICAL | 9.1 | 1.6% | Aug 26, 2021 | IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of... |
| CVE-2021-32648 | CRITICAL | 9.1 | 90.4% | Aug 26, 2021 | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an a... |
| CVE-2021-40147 | CRITICAL | 9.8 | 1.1% | Aug 26, 2021 | EmTec ZOC before 8.02.2 allows \e[201~ pastes, a different vulnerability than CVE-2021-32198. |
| CVE-2021-27944 | CRITICAL | 9.8 | 3.5% | Aug 26, 2021 | Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access cont... |
| CVE-2021-37334 | CRITICAL | 9.8 | 2.7% | Aug 25, 2021 | Umbraco Forms version 4.0.0 up to and including 8.7.5 and below are vulnerable to a security flaw that could lead to a r... |
| CVE-2021-37154 | CRITICAL | 9.8 | 1.4% | Aug 25, 2021 | In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a ... |
| CVE-2021-37153 | CRITICAL | 9.8 | 1.2% | Aug 25, 2021 | ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authe... |
| CVE-2021-1581 | CRITICAL | 9.1 | 1.1% | Aug 25, 2021 | Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or... |
| CVE-2021-1577 | CRITICAL | 9.1 | 1.3% | Aug 25, 2021 | A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Applicat... |
| CVE-2021-39159 | CRITICAL | 9.8 | 1.9% | Aug 25, 2021 | BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments... |
| CVE-2021-33885 | CRITICAL | 9.8 | 5.6% | Aug 25, 2021 | An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remot... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now