2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-29922CRITICAL9.1library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginni...
CVE-2021-38148CRITICAL9.8Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.
CVE-2021-20597CRITICAL9.1Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/3...
CVE-2021-26606CRITICAL9.8A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability i...
CVE-2021-37549CRITICAL9.1In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
CVE-2021-37544CRITICAL9.8In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
CVE-2021-36707CRITICAL9.8In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter...
CVE-2021-36706CRITICAL9.8In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter ...
CVE-2021-36705CRITICAL9.8In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter va...
CVE-2021-36351CRITICAL9.8SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth...
CVE-2021-36209CRITICAL9.8In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
CVE-2021-37388CRITICAL9.8A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an att...
CVE-2021-35327CRITICAL9.8A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, th...
CVE-2021-35324CRITICAL9.8A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to b...
CVE-2021-26605CRITICAL9.8An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. T...
CVE-2021-21805CRITICAL9.8An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10....
CVE-2021-34371CRITICAL9.8Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, ...
CVE-2021-29978CRITICAL9.8Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd pa...
CVE-2021-29971CRITICAL9.8If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespectiv...
CVE-2021-36800CRITICAL9.1Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. ...
CVE-2021-20028CRITICAL9.8Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Acce...
CVE-2021-1609CRITICAL9.8Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV3...
CVE-2021-1602CRITICAL9.8A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W V...
CVE-2021-37232CRITICAL9.8A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due...
CVE-2021-30571CRITICAL9.6Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now