2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32522 | CRITICAL | 9.8 | 1.4% | Jul 7, 2021 | Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remo... |
| CVE-2021-32521 | CRITICAL | 9.8 | 0.7% | Jul 7, 2021 | Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate ... |
| CVE-2021-32520 | CRITICAL | 9.8 | 1.0% | Jul 7, 2021 | Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials ... |
| CVE-2021-32513 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attac... |
| CVE-2021-32512 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated atta... |
| CVE-2021-34624 | CRITICAL | 9.8 | 6.7% | Jul 7, 2021 | A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress Word... |
| CVE-2021-34623 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress Wo... |
| CVE-2021-34621 | CRITICAL | 9.8 | 68.9% | Jul 7, 2021 | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr... |
| CVE-2021-25952 | CRITICAL | 9.8 | 3.3% | Jul 7, 2021 | Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial o... |
| CVE-2021-20776 | CRITICAL | 9.8 | 1.3% | Jul 7, 2021 | Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction an... |
| CVE-2021-24384 | CRITICAL | 9.8 | 2.1% | Jul 6, 2021 | The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated an... |
| CVE-2021-24375 | CRITICAL | 9.8 | 2.6% | Jul 6, 2021 | Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_qui... |
| CVE-2021-35209 | CRITICAL | 9.8 | 3.0% | Jul 2, 2021 | An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch... |
| CVE-2021-23403 | CRITICAL | 9.8 | 1.3% | Jul 2, 2021 | All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validati... |
| CVE-2021-32639 | CRITICAL | 9.9 | 1.4% | Jul 2, 2021 | Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forger... |
| CVE-2021-23402 | CRITICAL | 9.8 | 1.2% | Jul 2, 2021 | All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality. |
| CVE-2021-36128 | CRITICAL | 9.8 | 1.5% | Jul 2, 2021 | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppre... |
| CVE-2021-36126 | CRITICAL | 9.8 | 1.2% | Jul 2, 2021 | An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker mes... |
| CVE-2021-35029 | CRITICAL | 9.8 | 2.3% | Jul 2, 2021 | An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versio... |
| CVE-2021-35042 | CRITICAL | 9.8 | 44.4% | Jul 2, 2021 | Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input ... |
| CVE-2021-35336 | CRITICAL | 9.8 | 11.6% | Jul 1, 2021 | Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web A... |
| CVE-2021-22343 | CRITICAL | 9.1 | 0.7% | Jul 1, 2021 | There is a Configuration Defect vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may af... |
| CVE-2021-36088 | CRITICAL | 9.8 | 2.4% | Jul 1, 2021 | Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_pa... |
| CVE-2021-28804 | CRITICAL | 9.8 | 1.8% | Jul 1, 2021 | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability all... |
| CVE-2021-28802 | CRITICAL | 9.8 | 1.8% | Jul 1, 2021 | A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability all... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now