2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-29462CRITICAL9.8The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server pa...
CVE-2021-28827CRITICAL9.6The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ...
CVE-2021-28793CRITICAL9.8vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folde...
CVE-2021-23381CRITICAL9.8This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker...
CVE-2021-23379CRITICAL9.8This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an att...
CVE-2021-23378CRITICAL9.8This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is poss...
CVE-2021-23377CRITICAL9.8This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, i...
CVE-2021-23376CRITICAL9.8This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, ...
CVE-2021-23375CRITICAL9.8This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is poss...
CVE-2021-23374CRITICAL9.8This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is ...
CVE-2021-29451CRITICAL9.1Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signat...
CVE-2021-26830CRITICAL9.1SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin...
CVE-2021-31414CRITICAL9.8The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted ...
CVE-2021-27692CRITICAL9.8Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows ...
CVE-2021-27691CRITICAL9.8Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 ...
CVE-2021-27112CRITICAL9.8LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php duri...
CVE-2021-27850CRITICAL9.8A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The aff...
CVE-2021-30459CRITICAL9.8A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before ...
CVE-2021-27710CRITICAL9.8Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmwar...
CVE-2021-27708CRITICAL9.8Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmwar...
CVE-2021-27258CRITICAL9.8This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion ...
CVE-2021-27707CRITICAL9.8Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitra...
CVE-2021-27706CRITICAL9.8Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute...
CVE-2021-27705CRITICAL9.8Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitra...
CVE-2021-27130CRITICAL9.8Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a rev...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now