2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-31872CRITICAL9.8An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems...
CVE-2021-31870CRITICAL9.8An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow...
CVE-2021-21388CRITICAL9.8systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has...
CVE-2021-30234CRITICAL9.8The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute a...
CVE-2021-30233CRITICAL9.8The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arb...
CVE-2021-30232CRITICAL9.8The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute ...
CVE-2021-30231CRITICAL9.8The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbit...
CVE-2021-30230CRITICAL9.8The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execu...
CVE-2021-30228CRITICAL9.8The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execut...
CVE-2021-25812CRITICAL9.8Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/...
CVE-2021-27651CRITICAL9.8In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp...
CVE-2021-20090CRITICAL9.8A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 ...
CVE-2021-29145CRITICAL9.8A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy...
CVE-2021-31875CRITICAL9.8In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buff...
CVE-2021-25216CRITICAL9.8In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BI...
CVE-2021-22514CRITICAL9.8An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9...
CVE-2021-30168CRITICAL9.8The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant adminis...
CVE-2021-30167CRITICAL9.8The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL ...
CVE-2021-31856CRITICAL9.8A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL comman...
CVE-2021-20716CRITICAL9.8Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 ...
CVE-2021-29476CRITICAL9.8Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been p...
CVE-2021-29441CRITICAL9.8Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver...
CVE-2021-30128CRITICAL9.8Apache OFBiz has unsafe deserialization prior to 17.12.07 version
CVE-2021-29200CRITICAL9.8Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
CVE-2021-30642CRITICAL9.8An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now