2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29102 | CRITICAL | 9.1 | 1.6% | Jul 11, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote,... |
| CVE-2021-24020 | CRITICAL | 9.8 | 0.6% | Jul 9, 2021 | A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.... |
| CVE-2021-24007 | CRITICAL | 9.8 | 1.4% | Jul 9, 2021 | Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow... |
| CVE-2021-32742 | CRITICAL | 9.1 | 1.2% | Jul 9, 2021 | Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens ... |
| CVE-2021-30118 | CRITICAL | 9.8 | 60.1% | Jul 9, 2021 | An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Man... |
| CVE-2021-30116 | CRITICAL | 9.8 | 85.6% | Jul 9, 2021 | Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on pr... |
| CVE-2021-25437 | CRITICAL | 9.8 | 2.4% | Jul 8, 2021 | Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers t... |
| CVE-2021-25436 | CRITICAL | 9.8 | 1.6% | Jul 8, 2021 | Improper input validation vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows arbitrary... |
| CVE-2021-25435 | CRITICAL | 9.8 | 1.7% | Jul 8, 2021 | Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary c... |
| CVE-2021-25434 | CRITICAL | 9.8 | 1.7% | Jul 8, 2021 | Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary c... |
| CVE-2021-21821 | CRITICAL | 9.8 | 2.0% | Jul 8, 2021 | A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9.... |
| CVE-2021-28809 | CRITICAL | 9.8 | 15.8% | Jul 8, 2021 | An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, thi... |
| CVE-2021-21807 | CRITICAL | 9.8 | 1.5% | Jul 7, 2021 | An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A ... |
| CVE-2021-32714 | CRITICAL | 9.1 | 1.1% | Jul 7, 2021 | hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that cou... |
| CVE-2021-33221 | CRITICAL | 9.8 | 57.0% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints. |
| CVE-2021-33219 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Adm... |
| CVE-2021-33218 | CRITICAL | 9.8 | 2.3% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords th... |
| CVE-2021-33216 | CRITICAL | 9.8 | 13.8% | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowin... |
| CVE-2021-32538 | CRITICAL | 9.8 | 2.0% | Jul 7, 2021 | ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers ca... |
| CVE-2021-32535 | CRITICAL | 9.8 | 1.4% | Jul 7, 2021 | The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain admi... |
| CVE-2021-32534 | CRITICAL | 9.8 | 1.9% | Jul 7, 2021 | QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inj... |
| CVE-2021-32533 | CRITICAL | 9.8 | 1.9% | Jul 7, 2021 | The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject an... |
| CVE-2021-32531 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands w... |
| CVE-2021-32530 | CRITICAL | 9.8 | 2.3% | Jul 7, 2021 | OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arb... |
| CVE-2021-32529 | CRITICAL | 9.8 | 2.3% | Jul 7, 2021 | Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary command... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now