2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-22345CRITICAL9.8There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cau...
CVE-2021-22348CRITICAL9.8There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vu...
CVE-2021-22367CRITICAL9.8There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may l...
CVE-2021-22354CRITICAL9.1There is an Information Disclosure Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may...
CVE-2021-35973CRITICAL9.8NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, a...
CVE-2021-35971CRITICAL9.8Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserializati...
CVE-2021-22373CRITICAL9.1There is a Defects Introduced in the Design Process Vulnerability in Huawei Smartphone. Successful exploitation of this ...
CVE-2021-22323CRITICAL9.8There is an Integer Overflow Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may es...
CVE-2021-22380CRITICAL9.1There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation o...
CVE-2021-22375CRITICAL9.8There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may a...
CVE-2021-27903CRITICAL9.8An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerabilit...
CVE-2021-30648CRITICAL9.8The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypa...
CVE-2021-35474CRITICAL9.8Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic...
CVE-2021-35958CRITICAL9.1TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_fil...
CVE-2021-32992CRITICAL9.8FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory ...
CVE-2021-32990CRITICAL9.8FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attack...
CVE-2021-32988CRITICAL9.8FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attac...
CVE-2021-31531CRITICAL9.8Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
CVE-2021-31838CRITICAL9.1A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to t...
CVE-2021-34187CRITICAL9.8main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 p...
CVE-2021-35456CRITICAL9.8Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload
CVE-2021-31337CRITICAL9.8The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authenticati...
CVE-2021-35514CRITICAL9.8Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
CVE-2021-23399CRITICAL9.8This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, ...
CVE-2021-35502CRITICAL9.8app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data rel...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now