2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33679 | MEDIUM | 5.4 | 0.5% | Sep 14, 2021 | The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject... |
| CVE-2021-33675 | MEDIUM | 6.1 | 0.8% | Sep 14, 2021 | Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This al... |
| CVE-2021-33674 | MEDIUM | 6.1 | 0.7% | Sep 14, 2021 | Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This al... |
| CVE-2021-33673 | MEDIUM | 6.1 | 0.8% | Sep 14, 2021 | Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persi... |
| CVE-2021-32202 | MEDIUM | 6.1 | 0.6% | Sep 14, 2021 | In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the b... |
| CVE-2021-21489 | MEDIUM | 4.8 | 0.6% | Sep 14, 2021 | SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user r... |
| CVE-2021-40357 | MEDIUM | 4.9 | 1.1% | Sep 14, 2021 | A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.10), Teamcenter Active Work... |
| CVE-2021-37193 | MEDIUM | 4.3 | 0.4% | Sep 14, 2021 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attack... |
| CVE-2021-37192 | MEDIUM | 4.3 | 0.4% | Sep 14, 2021 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has... |
| CVE-2021-37191 | MEDIUM | 4.3 | 0.4% | Sep 14, 2021 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attack... |
| CVE-2021-37190 | MEDIUM | 4.3 | 0.4% | Sep 14, 2021 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has... |
| CVE-2021-37186 | MEDIUM | 5.4 | 0.3% | Sep 14, 2021 | A vulnerability has been identified in LOGO! CMR2020 (All versions < V2.2), LOGO! CMR2040 (All versions < V2.2), SIMATIC... |
| CVE-2021-37183 | MEDIUM | 6.5 | 0.4% | Sep 14, 2021 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software all... |
| CVE-2021-37177 | MEDIUM | 6.5 | 0.4% | Sep 14, 2021 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by th... |
| CVE-2021-37175 | MEDIUM | 5.3 | 0.7% | Sep 14, 2021 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions... |
| CVE-2021-33716 | MEDIUM | 6.5 | 0.2% | Sep 14, 2021 | A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-... |
| CVE-2021-39125 | MEDIUM | 5.3 | 1.4% | Sep 14, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of... |
| CVE-2021-39124 | MEDIUM | 4.3 | 0.5% | Sep 14, 2021 | The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16... |
| CVE-2021-39118 | MEDIUM | 5.3 | 1.4% | Sep 14, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full nam... |
| CVE-2021-33365 | MEDIUM | 5.5 | 0.8% | Sep 13, 2021 | Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted fi... |
| CVE-2021-33363 | MEDIUM | 5.5 | 0.8% | Sep 13, 2021 | Memory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file. |
| CVE-2021-33361 | MEDIUM | 5.5 | 0.9% | Sep 13, 2021 | Memory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file. |
| CVE-2021-32139 | MEDIUM | 5.5 | 0.7% | Sep 13, 2021 | The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference... |
| CVE-2021-32138 | MEDIUM | 5.5 | 0.7% | Sep 13, 2021 | The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a ... |
| CVE-2021-40824 | MEDIUM | 5.9 | 0.6% | Sep 13, 2021 | A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now