2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44233HIGH8.8SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for a...
CVE-2021-44232HIGH7.7SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided b...
CVE-2021-44231CRITICAL9.8Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An att...
CVE-2021-42367MEDIUM5.4The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several paramet...
CVE-2021-42070LOW3.3When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterpris...
CVE-2021-42069LOW3.3When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Ente...
CVE-2021-42068LOW3.3When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - ver...
CVE-2021-42066MEDIUM4.4SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should o...
CVE-2021-42064CRITICAL9.8If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterize...
CVE-2021-42063MEDIUM6.1A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage...
CVE-2021-42061MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-c...
CVE-2021-41836MEDIUM4.8The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ...
CVE-2021-41067HIGH7.5An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of sof...
CVE-2021-41066HIGH7.5An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions ...
CVE-2021-41065HIGH7.3An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wa...
CVE-2021-3836MEDIUM5.5dbeaver is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2021-39319MEDIUM6.1The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg pa...
CVE-2021-39318MEDIUM6.1The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found...
CVE-2021-39315MEDIUM6.1The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the...
CVE-2021-39314MEDIUM6.1The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter foun...
CVE-2021-39313MEDIUM6.1The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in...
CVE-2021-39312HIGH7.5The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp...
CVE-2021-39311MEDIUM6.1The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found ...
CVE-2021-39310MEDIUM6.1The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/re...
CVE-2021-39309MEDIUM6.1The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parame...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now