2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-35961CRITICAL9.8Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that ...
CVE-2021-21820CRITICAL9.8A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A sp...
CVE-2021-21804CRITICAL9.8A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12...
CVE-2021-0276CRITICAL9.8A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol...
CVE-2021-34690CRITICAL9.8iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass ...
CVE-2021-25320CRITICAL9.9A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by cr...
CVE-2021-35211CRITICAL10Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Mem...
CVE-2021-34523CRITICAL9Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-34473CRITICAL9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-22779CRITICAL9.1Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, i...
CVE-2021-0515CRITICAL9.8In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds ch...
CVE-2021-25953CRITICAL9.8Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of serv...
CVE-2021-21994CRITICAL9.8SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with net...
CVE-2021-31217CRITICAL9.1In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
CVE-2021-34552CRITICAL9.8Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters ...
CVE-2021-36124CRITICAL9.8An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when access...
CVE-2021-33578CRITICAL9.8Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticat...
CVE-2021-1965CRITICAL9.8Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdrago...
CVE-2021-32726CRITICAL9.8Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, web...
CVE-2021-24442CRITICAL9.8The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the...
CVE-2021-24385CRITICAL9.8The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user inp...
CVE-2021-23390CRITICAL9.8The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
CVE-2021-23389CRITICAL9.8The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
CVE-2021-26088CRITICAL9.6An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user t...
CVE-2021-35064CRITICAL9.8KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now