2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29462 | CRITICAL | 9.8 | 0.6% | Apr 20, 2021 | The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server pa... |
| CVE-2021-28827 | CRITICAL | 9.6 | 1.1% | Apr 20, 2021 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ... |
| CVE-2021-28793 | CRITICAL | 9.8 | 1.6% | Apr 20, 2021 | vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folde... |
| CVE-2021-23381 | CRITICAL | 9.8 | 1.3% | Apr 18, 2021 | This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker... |
| CVE-2021-23379 | CRITICAL | 9.8 | 1.3% | Apr 18, 2021 | This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an att... |
| CVE-2021-23378 | CRITICAL | 9.8 | 1.9% | Apr 18, 2021 | This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is poss... |
| CVE-2021-23377 | CRITICAL | 9.8 | 3.0% | Apr 18, 2021 | This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, i... |
| CVE-2021-23376 | CRITICAL | 9.8 | 1.9% | Apr 18, 2021 | This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, ... |
| CVE-2021-23375 | CRITICAL | 9.8 | 1.3% | Apr 18, 2021 | This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is poss... |
| CVE-2021-23374 | CRITICAL | 9.8 | 1.3% | Apr 18, 2021 | This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is ... |
| CVE-2021-29451 | CRITICAL | 9.1 | 0.9% | Apr 16, 2021 | Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signat... |
| CVE-2021-26830 | CRITICAL | 9.1 | 4.6% | Apr 16, 2021 | SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin... |
| CVE-2021-31414 | CRITICAL | 9.8 | 2.4% | Apr 16, 2021 | The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted ... |
| CVE-2021-27692 | CRITICAL | 9.8 | 3.3% | Apr 16, 2021 | Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows ... |
| CVE-2021-27691 | CRITICAL | 9.8 | 25.2% | Apr 16, 2021 | Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 ... |
| CVE-2021-27112 | CRITICAL | 9.8 | 2.4% | Apr 15, 2021 | LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php duri... |
| CVE-2021-27850 | CRITICAL | 9.8 | 94.1% | Apr 15, 2021 | A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The aff... |
| CVE-2021-30459 | CRITICAL | 9.8 | 1.9% | Apr 14, 2021 | A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before ... |
| CVE-2021-27710 | CRITICAL | 9.8 | 7.9% | Apr 14, 2021 | Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmwar... |
| CVE-2021-27708 | CRITICAL | 9.8 | 7.6% | Apr 14, 2021 | Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmwar... |
| CVE-2021-27258 | CRITICAL | 9.8 | 4.0% | Apr 14, 2021 | This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion ... |
| CVE-2021-27707 | CRITICAL | 9.8 | 2.8% | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitra... |
| CVE-2021-27706 | CRITICAL | 9.8 | 2.8% | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute... |
| CVE-2021-27705 | CRITICAL | 9.8 | 2.9% | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitra... |
| CVE-2021-27130 | CRITICAL | 9.8 | 2.2% | Apr 14, 2021 | Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a rev... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now