2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31184 | MEDIUM | 5.5 | 1.6% | May 11, 2021 | Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability |
| CVE-2021-31178 | MEDIUM | 5.5 | 16.0% | May 11, 2021 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2021-31174 | MEDIUM | 5.5 | 2.9% | May 11, 2021 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2021-31173 | MEDIUM | 5.3 | 2.1% | May 11, 2021 | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2021-31171 | MEDIUM | 4.1 | 0.6% | May 11, 2021 | Microsoft SharePoint Information Disclosure Vulnerability |
| CVE-2021-28479 | MEDIUM | 5.5 | 0.8% | May 11, 2021 | Windows CSC Service Information Disclosure Vulnerability |
| CVE-2021-28461 | MEDIUM | 6.1 | 1.3% | May 11, 2021 | Dynamics Finance and Operations Cross-site Scripting Vulnerability |
| CVE-2021-26421 | MEDIUM | 6.5 | 1.4% | May 11, 2021 | Skype for Business and Lync Spoofing Vulnerability |
| CVE-2021-26418 | MEDIUM | 4.6 | 1.2% | May 11, 2021 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2021-32573 | MEDIUM | 4.8 | 0.5% | May 11, 2021 | The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for produ... |
| CVE-2021-31537 | MEDIUM | 6.1 | 7.8% | May 11, 2021 | SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, p... |
| CVE-2021-29471 | MEDIUM | 5.3 | 1.6% | May 11, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-27619 | MEDIUM | 6.5 | 0.8% | May 11, 2021 | SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for at... |
| CVE-2021-27618 | MEDIUM | 4.9 | 0.8% | May 11, 2021 | The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does n... |
| CVE-2021-27617 | MEDIUM | 4.9 | 0.8% | May 11, 2021 | The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does n... |
| CVE-2021-27612 | MEDIUM | 6.1 | 0.6% | May 11, 2021 | In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious... |
| CVE-2021-27611 | MEDIUM | 6.7 | 0.3% | May 11, 2021 | SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by ... |
| CVE-2021-21654 | MEDIUM | 4.3 | 1.3% | May 11, 2021 | Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers w... |
| CVE-2021-21653 | MEDIUM | 4.3 | 0.9% | May 11, 2021 | Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint... |
| CVE-2021-21651 | MEDIUM | 4.3 | 0.7% | May 11, 2021 | Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attacke... |
| CVE-2021-21650 | MEDIUM | 4.3 | 0.7% | May 11, 2021 | Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoint... |
| CVE-2021-21649 | MEDIUM | 5.4 | 72.7% | May 11, 2021 | Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in... |
| CVE-2021-21648 | MEDIUM | 6.1 | 11.3% | May 11, 2021 | Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulti... |
| CVE-2021-32561 | MEDIUM | 6.1 | 1.1% | May 11, 2021 | OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters. |
| CVE-2021-32560 | MEDIUM | 6.5 | 1.5% | May 11, 2021 | The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that ar... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now