2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-20721CRITICAL9.8KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the fil...
CVE-2021-20720CRITICAL9.8SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL co...
CVE-2021-33204CRITICAL9.8In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achi...
CVE-2021-31324CRITICAL9.8The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root R...
CVE-2021-31316CRITICAL9.8The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST param...
CVE-2021-32305CRITICAL9.8WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet...
CVE-2021-24314CRITICAL9.8The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing pag...
CVE-2021-27734CRITICAL9.8Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers...
CVE-2021-22668CRITICAL9.8Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulne...
CVE-2021-3402CRITICAL9.1An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could ...
CVE-2021-25943CRITICAL9.8Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service ...
CVE-2021-25941CRITICAL9.8Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial o...
CVE-2021-24285CRITICAL9.8The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available...
CVE-2021-24284CRITICAL9.8The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'upload...
CVE-2021-33026CRITICAL9.8The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e...
CVE-2021-32615CRITICAL9.8Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
CVE-2021-23910CRITICAL9.8An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is a...
CVE-2021-23909CRITICAL9.8An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MC...
CVE-2021-23908CRITICAL9.8An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A t...
CVE-2021-23907CRITICAL9.8An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The...
CVE-2021-20999CRITICAL9.8In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usag...
CVE-2021-20998CRITICAL9.8In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it i...
CVE-2021-28799CRITICAL9.8An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exp...
CVE-2021-32608CRITICAL9.8An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does no...
CVE-2021-32607CRITICAL9.8An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now