2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40456 | MEDIUM | 5.3 | 2.2% | Oct 13, 2021 | Windows AD FS Security Feature Bypass Vulnerability |
| CVE-2021-40455 | MEDIUM | 5.5 | 0.5% | Oct 13, 2021 | Windows Installer Spoofing Vulnerability |
| CVE-2021-40454 | MEDIUM | 5.5 | 0.5% | Oct 13, 2021 | Rich Text Edit Control Information Disclosure Vulnerability |
| CVE-2021-38663 | MEDIUM | 5.5 | 0.7% | Oct 13, 2021 | Windows exFAT File System Information Disclosure Vulnerability |
| CVE-2021-38662 | MEDIUM | 5.5 | 0.8% | Oct 13, 2021 | Windows Fast FAT File System Driver Information Disclosure Vulnerability |
| CVE-2021-20031 | MEDIUM | 6.1 | 13.0% | Oct 12, 2021 | A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management ... |
| CVE-2021-3322 | MEDIUM | 6.5 | 0.5% | Oct 12, 2021 | Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr. Zephyr versions >= >=2.4.0 contain NULL Pointe... |
| CVE-2021-42326 | MEDIUM | 5.3 | 1.1% | Oct 12, 2021 | Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient acc... |
| CVE-2021-38915 | MEDIUM | 6.5 | 0.5% | Oct 12, 2021 | IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM ... |
| CVE-2021-40292 | MEDIUM | 5.4 | 0.5% | Oct 12, 2021 | A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter. |
| CVE-2021-3671 | MEDIUM | 6.5 | 2.0% | Oct 12, 2021 | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting... |
| CVE-2021-35494 | MEDIUM | 5.3 | 0.5% | Oct 12, 2021 | The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperRepo... |
| CVE-2021-27003 | MEDIUM | 4.7 | 0.6% | Oct 12, 2021 | Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header whi... |
| CVE-2021-37735 | MEDIUM | 5.3 | 1.2% | Oct 12, 2021 | A remote denial of service vulnerability was discovered in Aruba Instant version(s): Aruba Instant 6.5.x.x: 6.5.4.18 and... |
| CVE-2021-37734 | MEDIUM | 6.5 | 0.9% | Oct 12, 2021 | A remote unauthorized read access to files vulnerability was discovered in Aruba Instant version(s): 6.4.x.x: 6.4.4.8-4.... |
| CVE-2021-35214 | MEDIUM | 4.7 | 1.8% | Oct 12, 2021 | The vulnerability in SolarWinds Pingdom can be described as a failure to invalidate user session upon password or email ... |
| CVE-2021-40498 | MEDIUM | 5.5 | 0.2% | Oct 12, 2021 | A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, whi... |
| CVE-2021-40497 | MEDIUM | 5.3 | 0.8% | Oct 12, 2021 | SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application e... |
| CVE-2021-40496 | MEDIUM | 4.3 | 0.9% | Oct 12, 2021 | SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 7... |
| CVE-2021-40495 | MEDIUM | 5.3 | 1.0% | Oct 12, 2021 | There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - ve... |
| CVE-2021-38183 | MEDIUM | 6.1 | 0.7% | Oct 12, 2021 | SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker t... |
| CVE-2021-38179 | MEDIUM | 4.9 | 0.8% | Oct 12, 2021 | Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the capt... |
| CVE-2021-33727 | MEDIUM | 6.5 | 0.8% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could dow... |
| CVE-2021-33723 | MEDIUM | 6.5 | 0.6% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could cha... |
| CVE-2021-33722 | MEDIUM | 4.9 | 0.8% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system has a Path Trav... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now