2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27232HIGH8.8The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stac...
CVE-2021-25648CRITICAL9.8Mobile application "Testes de Codigo" 11.4 and prior allows an attacker to gain access to the administrative interface a...
CVE-2021-27236CRITICAL9.8An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion,...
CVE-2021-27235MEDIUM4.9An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, there is a f...
CVE-2021-27234CRITICAL9.8An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. The web application suffers from SQL injection on Adminl...
CVE-2021-27233MEDIUM4.9An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password inf...
CVE-2021-27231MEDIUM5.4Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to cr...
CVE-2021-27229HIGH8.8Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on t...
CVE-2021-21511HIGH8.1Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote l...
CVE-2021-3239CRITICAL9.8E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to exec...
CVE-2021-26822CRITICAL9.8Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in ...
CVE-2021-26201CRITICAL9.8The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attack...
CVE-2021-26200CRITICAL9.8The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login...
CVE-2021-27211HIGH7.5steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.
CVE-2021-27201HIGH8.8Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell m...
CVE-2021-3375CRITICAL9.8ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or a...
CVE-2021-27219HIGH7.5An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer ov...
CVE-2021-27218HIGH7.5An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with...
CVE-2021-23338HIGH7.2This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load funct...
CVE-2021-25299MEDIUM6.1Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/na...
CVE-2021-25298HIGH8.8Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi...
CVE-2021-25297HIGH8.8Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi...
CVE-2021-25296HIGH8.8Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi...
CVE-2021-23337HIGH7.2Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
CVE-2021-23336MEDIUM5.9The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now