2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-28300CRITICAL9.8NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to e...
CVE-2021-27114CRITICAL9.8An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment ...
CVE-2021-27113CRITICAL9.8An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const...
CVE-2021-28797CRITICAL9.8A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. I...
CVE-2021-31162CRITICAL9.8In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the ele...
CVE-2021-24028CRITICAL9.8An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code e...
CVE-2021-3460CRITICAL9.8The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communicat...
CVE-2021-28483CRITICAL9Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-28481CRITICAL9.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-28480CRITICAL9.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-27602CRITICAL9.9SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create ...
CVE-2021-23281CRITICAL10Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability...
CVE-2021-23280CRITICAL9.9Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. ...
CVE-2021-23279CRITICAL10Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability...
CVE-2021-23278CRITICAL9.6Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability i...
CVE-2021-23277CRITICAL10Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The s...
CVE-2021-0430CRITICAL9.8In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could...
CVE-2021-29999CRITICAL9.8An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server.
CVE-2021-29998CRITICAL9.8An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.
CVE-2021-21730CRITICAL9.8A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to acc...
CVE-2021-30176CRITICAL9.8The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/dev...
CVE-2021-30175CRITICAL9.8ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
CVE-2021-22505CRITICAL9.8Escalation of privileges vulnerability in Micro Focus Operations Agent, affects versions 12.0x, 12.10, 12.11, 12.12, 12....
CVE-2021-29943CRITICAL9.1When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/p...
CVE-2021-27905CRITICAL9.8The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now