2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-38171CRITICAL9.8adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a n...
CVE-2021-21828CRITICAL9.8A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xm...
CVE-2021-21827CRITICAL9.8A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xm...
CVE-2021-21826CRITICAL9.8A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xm...
CVE-2021-37597CRITICAL9.8WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
CVE-2021-39302CRITICAL9.8MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
CVE-2021-39274CRITICAL9.8In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing a...
CVE-2021-31226CRITICAL9.8An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parse...
CVE-2021-32588CRITICAL9.8A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 ...
CVE-2021-34730CRITICAL9.8A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W ...
CVE-2021-37358CRITICAL9.8SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_...
CVE-2021-21825CRITICAL9.8A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functio...
CVE-2021-37608CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote comma...
CVE-2021-21832CRITICAL9.8A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. ...
CVE-2021-21810CRITICAL9.8A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specia...
CVE-2021-22156CRITICAL9.8An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® ...
CVE-2021-3616CRITICAL9.8A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device...
CVE-2021-32829CRITICAL9.9ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of c...
CVE-2021-32827CRITICAL9.6MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An att...
CVE-2021-37708CRITICAL9.8Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in ma...
CVE-2021-32825CRITICAL9.1bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee438...
CVE-2021-22931CRITICAL9.8Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to miss...
CVE-2021-38754CRITICAL9.8SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
CVE-2021-38753CRITICAL9.8An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain ...
CVE-2021-35395CRITICAL9.8Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be u...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now