2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-33884CRITICAL9.1An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote...
CVE-2021-40084CRITICAL9.8opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For exam...
CVE-2021-39510CRITICAL9.8An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in t...
CVE-2021-39509CRITICAL9.8An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the ...
CVE-2021-31009CRITICAL9.8Multiple issues were addressed by removing HDF5. This issue is fixed in iOS 15.2 and iPadOS 15.2, macOS Monterey 12.1. M...
CVE-2021-30925CRITICAL9.1The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 an...
CVE-2021-30856CRITICAL9.1This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions....
CVE-2021-3711CRITICAL9.8In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically...
CVE-2021-26040CRITICAL9.1An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before execu...
CVE-2021-38306CRITICAL9.8Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS comma...
CVE-2021-37538CRITICAL9.8Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthentica...
CVE-2021-38613CRITICAL9.8The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any co...
CVE-2021-38611CRITICAL9.8A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attac...
CVE-2021-36385CRITICAL9.8A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary S...
CVE-2021-33191CRITICAL9.8From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to pat...
CVE-2021-23432CRITICAL9.8This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
CVE-2021-23406CRITICAL9.8This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC fil...
CVE-2021-39615CRITICAL9.8D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If...
CVE-2021-39614CRITICAL9.8D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak pass...
CVE-2021-39613CRITICAL9.8D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user acc...
CVE-2021-3694CRITICAL9.6LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an...
CVE-2021-3693CRITICAL9.6LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL ...
CVE-2021-24551CRITICAL9.8The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter...
CVE-2021-39290CRITICAL9.8Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4...
CVE-2021-38598CRITICAL9.1OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbrid...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now