2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20721 | CRITICAL | 9.8 | 1.5% | May 20, 2021 | KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the fil... |
| CVE-2021-20720 | CRITICAL | 9.8 | 1.3% | May 20, 2021 | SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL co... |
| CVE-2021-33204 | CRITICAL | 9.8 | 2.2% | May 19, 2021 | In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achi... |
| CVE-2021-31324 | CRITICAL | 9.8 | 34.1% | May 18, 2021 | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root R... |
| CVE-2021-31316 | CRITICAL | 9.8 | 13.0% | May 18, 2021 | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST param... |
| CVE-2021-32305 | CRITICAL | 9.8 | 86.7% | May 18, 2021 | WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet... |
| CVE-2021-24314 | CRITICAL | 9.8 | 1.9% | May 17, 2021 | The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing pag... |
| CVE-2021-27734 | CRITICAL | 9.8 | 1.3% | May 17, 2021 | Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers... |
| CVE-2021-22668 | CRITICAL | 9.8 | 1.8% | May 16, 2021 | Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulne... |
| CVE-2021-3402 | CRITICAL | 9.1 | 2.2% | May 14, 2021 | An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could ... |
| CVE-2021-25943 | CRITICAL | 9.8 | 3.3% | May 14, 2021 | Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service ... |
| CVE-2021-25941 | CRITICAL | 9.8 | 3.3% | May 14, 2021 | Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial o... |
| CVE-2021-24285 | CRITICAL | 9.8 | 14.7% | May 14, 2021 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available... |
| CVE-2021-24284 | CRITICAL | 9.8 | 42.1% | May 14, 2021 | The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'upload... |
| CVE-2021-33026 | CRITICAL | 9.8 | 7.3% | May 13, 2021 | The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e... |
| CVE-2021-32615 | CRITICAL | 9.8 | 2.1% | May 13, 2021 | Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection. |
| CVE-2021-23910 | CRITICAL | 9.8 | 1.7% | May 13, 2021 | An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is a... |
| CVE-2021-23909 | CRITICAL | 9.8 | 2.4% | May 13, 2021 | An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MC... |
| CVE-2021-23908 | CRITICAL | 9.8 | 2.4% | May 13, 2021 | An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A t... |
| CVE-2021-23907 | CRITICAL | 9.8 | 2.4% | May 13, 2021 | An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The... |
| CVE-2021-20999 | CRITICAL | 9.8 | 0.9% | May 13, 2021 | In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usag... |
| CVE-2021-20998 | CRITICAL | 9.8 | 1.1% | May 13, 2021 | In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it i... |
| CVE-2021-28799 | CRITICAL | 9.8 | 78.4% | May 13, 2021 | An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exp... |
| CVE-2021-32608 | CRITICAL | 9.8 | 33.4% | May 12, 2021 | An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does no... |
| CVE-2021-32607 | CRITICAL | 9.8 | 33.4% | May 12, 2021 | An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now