2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-21487HIGH8.8SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in ...
CVE-2021-21486HIGH8.8SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does n...
CVE-2021-21481HIGH8.8The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform...
CVE-2021-21480HIGH8.8SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). ...
CVE-2021-20276HIGH7.5A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may le...
CVE-2021-20275HIGH7.5A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to...
CVE-2021-20274HIGH7.5A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbeh...
CVE-2021-20273HIGH7.5A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.
CVE-2021-20272HIGH7.5A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to...
CVE-2021-21506HIGH8.8PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenti...
CVE-2021-21503HIGH7.8PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user co...
CVE-2021-21327HIGH7.5GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2021-26788HIGH7.5Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a de...
CVE-2021-27365HIGH7.8An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length...
CVE-2021-27364HIGH7.1An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by...
CVE-2021-26294HIGH7.5An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal...
CVE-2021-26814HIGH8.8Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileg...
CVE-2021-28042HIGH7.8Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload fea...
CVE-2021-28041HIGH7.1ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstra...
CVE-2021-27256HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R780...
CVE-2021-27255HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware...
CVE-2021-27254HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800...
CVE-2021-28040HIGH7.5An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number o...
CVE-2021-27098HIGH8.1In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the Fet...
CVE-2021-26964HIGH7.1A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s):...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now