2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-29102CRITICAL9.1A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote,...
CVE-2021-24020CRITICAL9.8A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6....
CVE-2021-24007CRITICAL9.8Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow...
CVE-2021-32742CRITICAL9.1Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens ...
CVE-2021-30118CRITICAL9.8An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Man...
CVE-2021-30116CRITICAL9.8Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on pr...
CVE-2021-25437CRITICAL9.8Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers t...
CVE-2021-25436CRITICAL9.8Improper input validation vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows arbitrary...
CVE-2021-25435CRITICAL9.8Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary c...
CVE-2021-25434CRITICAL9.8Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary c...
CVE-2021-21821CRITICAL9.8A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9....
CVE-2021-28809CRITICAL9.8An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, thi...
CVE-2021-21807CRITICAL9.8An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A ...
CVE-2021-32714CRITICAL9.1hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that cou...
CVE-2021-33221CRITICAL9.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
CVE-2021-33219CRITICAL9.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Adm...
CVE-2021-33218CRITICAL9.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords th...
CVE-2021-33216CRITICAL9.8An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowin...
CVE-2021-32538CRITICAL9.8ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers ca...
CVE-2021-32535CRITICAL9.8The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain admi...
CVE-2021-32534CRITICAL9.8QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inj...
CVE-2021-32533CRITICAL9.8The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject an...
CVE-2021-32531CRITICAL9.8OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands w...
CVE-2021-32530CRITICAL9.8OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arb...
CVE-2021-32529CRITICAL9.8Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary command...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now