2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34427 | CRITICAL | 9.8 | 57.7% | Jun 25, 2021 | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessibl... |
| CVE-2021-34074 | CRITICAL | 9.8 | 7.5% | Jun 25, 2021 | PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass t... |
| CVE-2021-34184 | CRITICAL | 9.8 | 1.1% | Jun 25, 2021 | Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in m... |
| CVE-2021-35048 | CRITICAL | 9.8 | 1.3% | Jun 25, 2021 | Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interfa... |
| CVE-2021-28958 | CRITICAL | 9.8 | 73.1% | Jun 25, 2021 | Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing ... |
| CVE-2021-33346 | CRITICAL | 9.8 | 1.2% | Jun 24, 2021 | There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this... |
| CVE-2021-31649 | CRITICAL | 9.8 | 1.8% | Jun 24, 2021 | In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerab... |
| CVE-2021-29954 | CRITICAL | 9.8 | 0.6% | Jun 24, 2021 | Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata s... |
| CVE-2021-28800 | CRITICAL | 9.8 | 1.4% | Jun 24, 2021 | A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, thi... |
| CVE-2021-21809 | CRITICAL | 9.1 | 24.2% | Jun 23, 2021 | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted s... |
| CVE-2021-21998 | CRITICAL | 9.8 | 10.6% | Jun 23, 2021 | VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A mal... |
| CVE-2021-27649 | CRITICAL | 9.8 | 2.0% | Jun 23, 2021 | Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-2542... |
| CVE-2021-3044 | CRITICAL | 9.8 | 1.4% | Jun 22, 2021 | An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker wit... |
| CVE-2021-20736 | CRITICAL | 9.1 | 1.3% | Jun 22, 2021 | NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the inf... |
| CVE-2021-35066 | CRITICAL | 9.8 | 1.1% | Jun 21, 2021 | An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. |
| CVE-2021-24376 | CRITICAL | 9.8 | 3.7% | Jun 21, 2021 | The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archiv... |
| CVE-2021-24370 | CRITICAL | 9.8 | 47.1% | Jun 21, 2021 | The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, res... |
| CVE-2021-24361 | CRITICAL | 9.8 | 1.8% | Jun 21, 2021 | In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sani... |
| CVE-2021-26461 | CRITICAL | 9.8 | 5.0% | Jun 21, 2021 | Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. T... |
| CVE-2021-0516 | CRITICAL | 9.8 | 1.6% | Jun 21, 2021 | In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This... |
| CVE-2021-31272 | CRITICAL | 9.8 | 3.2% | Jun 18, 2021 | SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/un... |
| CVE-2021-21410 | CRITICAL | 9.1 | 1.2% | Jun 18, 2021 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can... |
| CVE-2021-21281 | CRITICAL | 9.8 | 0.9% | Jun 18, 2021 | Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerab... |
| CVE-2021-21280 | CRITICAL | 9.8 | 1.1% | Jun 18, 2021 | Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an... |
| CVE-2021-21282 | CRITICAL | 9.8 | 1.0% | Jun 18, 2021 | Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now