2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-32522CRITICAL9.8Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remo...
CVE-2021-32521CRITICAL9.8Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate ...
CVE-2021-32520CRITICAL9.8Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials ...
CVE-2021-32513CRITICAL9.8QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attac...
CVE-2021-32512CRITICAL9.8QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated atta...
CVE-2021-34624CRITICAL9.8A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress Word...
CVE-2021-34623CRITICAL9.8A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress Wo...
CVE-2021-34621CRITICAL9.8A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr...
CVE-2021-25952CRITICAL9.8Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial o...
CVE-2021-20776CRITICAL9.8Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction an...
CVE-2021-24384CRITICAL9.8The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated an...
CVE-2021-24375CRITICAL9.8Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_qui...
CVE-2021-35209CRITICAL9.8An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch...
CVE-2021-23403CRITICAL9.8All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validati...
CVE-2021-32639CRITICAL9.9Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forger...
CVE-2021-23402CRITICAL9.8All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
CVE-2021-36128CRITICAL9.8An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppre...
CVE-2021-36126CRITICAL9.8An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker mes...
CVE-2021-35029CRITICAL9.8An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versio...
CVE-2021-35042CRITICAL9.8Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input ...
CVE-2021-35336CRITICAL9.8Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web A...
CVE-2021-22343CRITICAL9.1There is a Configuration Defect vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may af...
CVE-2021-36088CRITICAL9.8Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_pa...
CVE-2021-28804CRITICAL9.8A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability all...
CVE-2021-28802CRITICAL9.8A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability all...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now