2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-3805HIGH7.5object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-41314HIGH8.8Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several fau...
CVE-2021-29825HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_...
CVE-2021-41079HIGH7.5Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets...
CVE-2021-39239HIGH7.5A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External...
CVE-2021-36160HIGH7.5A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This ...
CVE-2021-34798HIGH7.5Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and ...
CVE-2021-39128HIGH7.2Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers...
CVE-2021-40639HIGH7.5Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.proper...
CVE-2021-40862HIGH8.8HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to a...
CVE-2021-33705HIGH8.1The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server...
CVE-2021-33704HIGH8.8The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that...
CVE-2021-33700HIGH7.8SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstance...
CVE-2021-33698HIGH8.8SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script f...
CVE-2021-33692HIGH7.5SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject ...
CVE-2021-40965HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that a...
CVE-2021-39215HIGH7.5Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the ...
CVE-2021-29750HIGH7.5IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h...
CVE-2021-40156HIGH7.8A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to write beyond allocated bou...
CVE-2021-40155HIGH7.8A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boun...
CVE-2021-3795HIGH7.5semver-regex is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-39213HIGH8.8GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with A...
CVE-2021-27046HIGH7.8A Memory Corruption vulnerability for PDF files in Autodesk Navisworks 2019, 2020, 2021, 2022 may lead to code execution...
CVE-2021-27045HIGH7.8A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boun...
CVE-2021-39209HIGH8.8GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now