2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33884 | CRITICAL | 9.1 | 1.0% | Aug 25, 2021 | An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote... |
| CVE-2021-40084 | CRITICAL | 9.8 | 2.7% | Aug 25, 2021 | opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For exam... |
| CVE-2021-39510 | CRITICAL | 9.8 | 8.6% | Aug 24, 2021 | An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in t... |
| CVE-2021-39509 | CRITICAL | 9.8 | 5.1% | Aug 24, 2021 | An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the ... |
| CVE-2021-31009 | CRITICAL | 9.8 | 1.2% | Aug 24, 2021 | Multiple issues were addressed by removing HDF5. This issue is fixed in iOS 15.2 and iPadOS 15.2, macOS Monterey 12.1. M... |
| CVE-2021-30925 | CRITICAL | 9.1 | 1.3% | Aug 24, 2021 | The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 an... |
| CVE-2021-30856 | CRITICAL | 9.1 | 0.9% | Aug 24, 2021 | This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions.... |
| CVE-2021-3711 | CRITICAL | 9.8 | 87.8% | Aug 24, 2021 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically... |
| CVE-2021-26040 | CRITICAL | 9.1 | 0.9% | Aug 24, 2021 | An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before execu... |
| CVE-2021-38306 | CRITICAL | 9.8 | 9.0% | Aug 24, 2021 | Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS comma... |
| CVE-2021-37538 | CRITICAL | 9.8 | 74.5% | Aug 24, 2021 | Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthentica... |
| CVE-2021-38613 | CRITICAL | 9.8 | 4.5% | Aug 24, 2021 | The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any co... |
| CVE-2021-38611 | CRITICAL | 9.8 | 1.9% | Aug 24, 2021 | A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attac... |
| CVE-2021-36385 | CRITICAL | 9.8 | 2.7% | Aug 24, 2021 | A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary S... |
| CVE-2021-33191 | CRITICAL | 9.8 | 4.0% | Aug 24, 2021 | From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to pat... |
| CVE-2021-23432 | CRITICAL | 9.8 | 0.9% | Aug 24, 2021 | This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge() |
| CVE-2021-23406 | CRITICAL | 9.8 | 2.9% | Aug 24, 2021 | This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC fil... |
| CVE-2021-39615 | CRITICAL | 9.8 | 2.2% | Aug 23, 2021 | D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If... |
| CVE-2021-39614 | CRITICAL | 9.8 | 1.7% | Aug 23, 2021 | D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak pass... |
| CVE-2021-39613 | CRITICAL | 9.8 | 1.7% | Aug 23, 2021 | D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user acc... |
| CVE-2021-3694 | CRITICAL | 9.6 | 2.4% | Aug 23, 2021 | LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an... |
| CVE-2021-3693 | CRITICAL | 9.6 | 3.0% | Aug 23, 2021 | LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL ... |
| CVE-2021-24551 | CRITICAL | 9.8 | 1.9% | Aug 23, 2021 | The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter... |
| CVE-2021-39290 | CRITICAL | 9.8 | 1.5% | Aug 23, 2021 | Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4... |
| CVE-2021-38598 | CRITICAL | 9.1 | 1.2% | Aug 23, 2021 | OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbrid... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now