2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3805 | HIGH | 7.5 | 2.0% | Sep 17, 2021 | object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-41314 | HIGH | 8.8 | 13.6% | Sep 16, 2021 | Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several fau... |
| CVE-2021-29825 | HIGH | 7.5 | 1.5% | Sep 16, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_... |
| CVE-2021-41079 | HIGH | 7.5 | 6.7% | Sep 16, 2021 | Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets... |
| CVE-2021-39239 | HIGH | 7.5 | 4.0% | Sep 16, 2021 | A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External... |
| CVE-2021-36160 | HIGH | 7.5 | 62.9% | Sep 16, 2021 | A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This ... |
| CVE-2021-34798 | HIGH | 7.5 | 64.5% | Sep 16, 2021 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and ... |
| CVE-2021-39128 | HIGH | 7.2 | 1.8% | Sep 16, 2021 | Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers... |
| CVE-2021-40639 | HIGH | 7.5 | 1.4% | Sep 15, 2021 | Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.proper... |
| CVE-2021-40862 | HIGH | 8.8 | 0.9% | Sep 15, 2021 | HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to a... |
| CVE-2021-33705 | HIGH | 8.1 | 2.0% | Sep 15, 2021 | The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server... |
| CVE-2021-33704 | HIGH | 8.8 | 0.6% | Sep 15, 2021 | The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that... |
| CVE-2021-33700 | HIGH | 7.8 | 0.2% | Sep 15, 2021 | SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstance... |
| CVE-2021-33698 | HIGH | 8.8 | 1.1% | Sep 15, 2021 | SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script f... |
| CVE-2021-33692 | HIGH | 7.5 | 1.1% | Sep 15, 2021 | SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject ... |
| CVE-2021-40965 | HIGH | 8.8 | 0.6% | Sep 15, 2021 | A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that a... |
| CVE-2021-39215 | HIGH | 7.5 | 1.2% | Sep 15, 2021 | Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the ... |
| CVE-2021-29750 | HIGH | 7.5 | 0.7% | Sep 15, 2021 | IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h... |
| CVE-2021-40156 | HIGH | 7.8 | 1.0% | Sep 15, 2021 | A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to write beyond allocated bou... |
| CVE-2021-40155 | HIGH | 7.8 | 1.0% | Sep 15, 2021 | A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boun... |
| CVE-2021-3795 | HIGH | 7.5 | 1.4% | Sep 15, 2021 | semver-regex is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-39213 | HIGH | 8.8 | 1.0% | Sep 15, 2021 | GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with A... |
| CVE-2021-27046 | HIGH | 7.8 | 0.3% | Sep 15, 2021 | A Memory Corruption vulnerability for PDF files in Autodesk Navisworks 2019, 2020, 2021, 2022 may lead to code execution... |
| CVE-2021-27045 | HIGH | 7.8 | 0.9% | Sep 15, 2021 | A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boun... |
| CVE-2021-39209 | HIGH | 8.8 | 0.5% | Sep 15, 2021 | GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now