2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35961 | CRITICAL | 9.8 | 2.2% | Jul 16, 2021 | Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that ... |
| CVE-2021-21820 | CRITICAL | 9.8 | 3.0% | Jul 16, 2021 | A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A sp... |
| CVE-2021-21804 | CRITICAL | 9.8 | 3.7% | Jul 16, 2021 | A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12... |
| CVE-2021-0276 | CRITICAL | 9.8 | 2.3% | Jul 15, 2021 | A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol... |
| CVE-2021-34690 | CRITICAL | 9.8 | 1.2% | Jul 15, 2021 | iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass ... |
| CVE-2021-25320 | CRITICAL | 9.9 | 0.8% | Jul 15, 2021 | A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by cr... |
| CVE-2021-35211 | CRITICAL | 10 | 91.2% | Jul 14, 2021 | Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Mem... |
| CVE-2021-34523 | CRITICAL | 9 | 100.0% | Jul 14, 2021 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-34473 | CRITICAL | 9.1 | 100.0% | Jul 14, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-22779 | CRITICAL | 9.1 | 1.0% | Jul 14, 2021 | Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, i... |
| CVE-2021-0515 | CRITICAL | 9.8 | 1.4% | Jul 14, 2021 | In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds ch... |
| CVE-2021-25953 | CRITICAL | 9.8 | 3.0% | Jul 14, 2021 | Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of serv... |
| CVE-2021-21994 | CRITICAL | 9.8 | 1.2% | Jul 13, 2021 | SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with net... |
| CVE-2021-31217 | CRITICAL | 9.1 | 3.8% | Jul 13, 2021 | In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. |
| CVE-2021-34552 | CRITICAL | 9.8 | 3.2% | Jul 13, 2021 | Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters ... |
| CVE-2021-36124 | CRITICAL | 9.8 | 1.1% | Jul 13, 2021 | An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when access... |
| CVE-2021-33578 | CRITICAL | 9.8 | 1.2% | Jul 13, 2021 | Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticat... |
| CVE-2021-1965 | CRITICAL | 9.8 | 3.0% | Jul 13, 2021 | Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdrago... |
| CVE-2021-32726 | CRITICAL | 9.8 | 1.8% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, web... |
| CVE-2021-24442 | CRITICAL | 9.8 | 46.9% | Jul 12, 2021 | The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the... |
| CVE-2021-24385 | CRITICAL | 9.8 | 2.8% | Jul 12, 2021 | The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user inp... |
| CVE-2021-23390 | CRITICAL | 9.8 | 2.9% | Jul 12, 2021 | The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. |
| CVE-2021-23389 | CRITICAL | 9.8 | 3.6% | Jul 12, 2021 | The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. |
| CVE-2021-26088 | CRITICAL | 9.6 | 1.0% | Jul 12, 2021 | An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user t... |
| CVE-2021-35064 | CRITICAL | 9.8 | 70.8% | Jul 12, 2021 | KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now