2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29922 | CRITICAL | 9.1 | 2.6% | Aug 7, 2021 | library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginni... |
| CVE-2021-38148 | CRITICAL | 9.8 | 1.2% | Aug 7, 2021 | Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs. |
| CVE-2021-20597 | CRITICAL | 9.1 | 2.2% | Aug 6, 2021 | Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/3... |
| CVE-2021-26606 | CRITICAL | 9.8 | 2.4% | Aug 6, 2021 | A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability i... |
| CVE-2021-37549 | CRITICAL | 9.1 | 1.3% | Aug 6, 2021 | In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient. |
| CVE-2021-37544 | CRITICAL | 9.8 | 1.2% | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization. |
| CVE-2021-36707 | CRITICAL | 9.8 | 2.6% | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter... |
| CVE-2021-36706 | CRITICAL | 9.8 | 2.6% | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter ... |
| CVE-2021-36705 | CRITICAL | 9.8 | 2.6% | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter va... |
| CVE-2021-36351 | CRITICAL | 9.8 | 1.9% | Aug 6, 2021 | SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth... |
| CVE-2021-36209 | CRITICAL | 9.8 | 1.0% | Aug 6, 2021 | In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset. |
| CVE-2021-37388 | CRITICAL | 9.8 | 3.7% | Aug 6, 2021 | A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an att... |
| CVE-2021-35327 | CRITICAL | 9.8 | 1.4% | Aug 5, 2021 | A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, th... |
| CVE-2021-35324 | CRITICAL | 9.8 | 10.4% | Aug 5, 2021 | A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to b... |
| CVE-2021-26605 | CRITICAL | 9.8 | 1.0% | Aug 5, 2021 | An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. T... |
| CVE-2021-21805 | CRITICAL | 9.8 | 69.6% | Aug 5, 2021 | An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.... |
| CVE-2021-34371 | CRITICAL | 9.8 | 13.4% | Aug 5, 2021 | Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, ... |
| CVE-2021-29978 | CRITICAL | 9.8 | 2.8% | Aug 5, 2021 | Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd pa... |
| CVE-2021-29971 | CRITICAL | 9.8 | 1.0% | Aug 5, 2021 | If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespectiv... |
| CVE-2021-36800 | CRITICAL | 9.1 | 1.5% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. ... |
| CVE-2021-20028 | CRITICAL | 9.8 | 30.1% | Aug 4, 2021 | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Acce... |
| CVE-2021-1609 | CRITICAL | 9.8 | 9.7% | Aug 4, 2021 | Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV3... |
| CVE-2021-1602 | CRITICAL | 9.8 | 2.0% | Aug 4, 2021 | A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W V... |
| CVE-2021-37232 | CRITICAL | 9.8 | 2.2% | Aug 4, 2021 | A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due... |
| CVE-2021-30571 | CRITICAL | 9.6 | 1.2% | Aug 3, 2021 | Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now