2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30181 | CRITICAL | 9.8 | 61.5% | Jun 1, 2021 | Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the r... |
| CVE-2021-30180 | CRITICAL | 9.8 | 60.4% | Jun 1, 2021 | Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. T... |
| CVE-2021-30179 | CRITICAL | 9.8 | 4.2% | Jun 1, 2021 | Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfa... |
| CVE-2021-25641 | CRITICAL | 9.8 | 17.7% | Jun 1, 2021 | Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. ... |
| CVE-2021-24321 | CRITICAL | 9.8 | 66.6% | Jun 1, 2021 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt... |
| CVE-2021-27828 | CRITICAL | 9.1 | 20.3% | Jun 1, 2021 | SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the a... |
| CVE-2021-33790 | CRITICAL | 9.8 | 2.8% | May 31, 2021 | The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputSt... |
| CVE-2021-33564 | CRITICAL | 9.8 | 72.2% | May 29, 2021 | An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write... |
| CVE-2021-31703 | CRITICAL | 9.8 | 1.2% | May 29, 2021 | Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by... |
| CVE-2021-30461 | CRITICAL | 9.8 | 36.6% | May 29, 2021 | A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,... |
| CVE-2021-32619 | CRITICAL | 9.8 | 1.1% | May 28, 2021 | Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, mod... |
| CVE-2021-22519 | CRITICAL | 9.8 | 2.0% | May 28, 2021 | Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), ... |
| CVE-2021-32642 | CRITICAL | 9.4 | 1.3% | May 28, 2021 | radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validatio... |
| CVE-2021-32637 | CRITICAL | 10 | 1.9% | May 28, 2021 | Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_req... |
| CVE-2021-20236 | CRITICAL | 9.8 | 1.6% | May 28, 2021 | A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buf... |
| CVE-2021-20195 | CRITICAL | 9.6 | 1.2% | May 28, 2021 | A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account... |
| CVE-2021-27852 | CRITICAL | 9.8 | 31.9% | May 27, 2021 | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote a... |
| CVE-2021-31535 | CRITICAL | 9.8 | 10.6% | May 27, 2021 | LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. T... |
| CVE-2021-22911 | CRITICAL | 9.8 | 95.2% | May 27, 2021 | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti... |
| CVE-2021-22891 | CRITICAL | 9.8 | 1.1% | May 27, 2021 | A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.... |
| CVE-2021-33590 | CRITICAL | 9.8 | 1.5% | May 27, 2021 | GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c. |
| CVE-2021-22738 | CRITICAL | 9.8 | 0.6% | May 26, 2021 | Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 an... |
| CVE-2021-22737 | CRITICAL | 9.8 | 0.9% | May 26, 2021 | Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that... |
| CVE-2021-22731 | CRITICAL | 9.8 | 1.4% | May 26, 2021 | Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSES... |
| CVE-2021-33470 | CRITICAL | 9.8 | 2.3% | May 26, 2021 | COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now