2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44233 | HIGH | 8.8 | 0.8% | Dec 14, 2021 | SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for a... |
| CVE-2021-44232 | HIGH | 7.7 | 1.0% | Dec 14, 2021 | SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided b... |
| CVE-2021-44231 | CRITICAL | 9.8 | 1.3% | Dec 14, 2021 | Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An att... |
| CVE-2021-42367 | MEDIUM | 5.4 | 0.5% | Dec 14, 2021 | The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several paramet... |
| CVE-2021-42070 | LOW | 3.3 | 0.5% | Dec 14, 2021 | When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterpris... |
| CVE-2021-42069 | LOW | 3.3 | 1.0% | Dec 14, 2021 | When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Ente... |
| CVE-2021-42068 | LOW | 3.3 | 0.5% | Dec 14, 2021 | When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - ver... |
| CVE-2021-42066 | MEDIUM | 4.4 | 0.4% | Dec 14, 2021 | SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should o... |
| CVE-2021-42064 | CRITICAL | 9.8 | 1.1% | Dec 14, 2021 | If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterize... |
| CVE-2021-42063 | MEDIUM | 6.1 | 22.3% | Dec 14, 2021 | A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage... |
| CVE-2021-42061 | MEDIUM | 5.4 | 0.5% | Dec 14, 2021 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-c... |
| CVE-2021-41836 | MEDIUM | 4.8 | 0.6% | Dec 14, 2021 | The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ... |
| CVE-2021-41067 | HIGH | 7.5 | 0.6% | Dec 14, 2021 | An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of sof... |
| CVE-2021-41066 | HIGH | 7.5 | 1.3% | Dec 14, 2021 | An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions ... |
| CVE-2021-41065 | HIGH | 7.3 | 0.5% | Dec 14, 2021 | An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wa... |
| CVE-2021-3836 | MEDIUM | 5.5 | 0.9% | Dec 14, 2021 | dbeaver is vulnerable to Improper Restriction of XML External Entity Reference |
| CVE-2021-39319 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg pa... |
| CVE-2021-39318 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found... |
| CVE-2021-39315 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the... |
| CVE-2021-39314 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter foun... |
| CVE-2021-39313 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in... |
| CVE-2021-39312 | HIGH | 7.5 | 78.4% | Dec 14, 2021 | The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp... |
| CVE-2021-39311 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found ... |
| CVE-2021-39310 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/re... |
| CVE-2021-39309 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | The Parsian Bank Gateway for Woocommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via and parame... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now