2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-34427CRITICAL9.8In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessibl...
CVE-2021-34074CRITICAL9.8PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass t...
CVE-2021-34184CRITICAL9.8Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in m...
CVE-2021-35048CRITICAL9.8Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interfa...
CVE-2021-28958CRITICAL9.8Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing ...
CVE-2021-33346CRITICAL9.8There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this...
CVE-2021-31649CRITICAL9.8In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerab...
CVE-2021-29954CRITICAL9.8Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata s...
CVE-2021-28800CRITICAL9.8A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, thi...
CVE-2021-21809CRITICAL9.1A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted s...
CVE-2021-21998CRITICAL9.8VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A mal...
CVE-2021-27649CRITICAL9.8Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-2542...
CVE-2021-3044CRITICAL9.8An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker wit...
CVE-2021-20736CRITICAL9.1NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the inf...
CVE-2021-35066CRITICAL9.8An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
CVE-2021-24376CRITICAL9.8The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archiv...
CVE-2021-24370CRITICAL9.8The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, res...
CVE-2021-24361CRITICAL9.8In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sani...
CVE-2021-26461CRITICAL9.8Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. T...
CVE-2021-0516CRITICAL9.8In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This...
CVE-2021-31272CRITICAL9.8SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/un...
CVE-2021-21410CRITICAL9.1Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can...
CVE-2021-21281CRITICAL9.8Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerab...
CVE-2021-21280CRITICAL9.8Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an...
CVE-2021-21282CRITICAL9.8Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now