2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3064CRITICAL9.8A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables ...
CVE-2021-3063HIGH7.5An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gatew...
CVE-2021-3062HIGH8.8An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProte...
CVE-2021-3061HIGH7.2An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authentic...
CVE-2021-3060HIGH8.1An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software al...
CVE-2021-3059HIGH8.1An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynam...
CVE-2021-3058HIGH7.2An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administra...
CVE-2021-3056HIGH8.8A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated att...
CVE-2021-43564HIGH7.5An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extens...
CVE-2021-43563HIGH8.8An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Cont...
CVE-2021-42062MEDIUM4.3SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employe...
CVE-2021-41427MEDIUM6.1Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.
CVE-2021-41426HIGH8.8Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.
CVE-2021-40521CRITICAL9.8Airangel HSMX Gateway devices through 5.2.04 allow Remote Code Execution.
CVE-2021-40519CRITICAL10Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials.
CVE-2021-40518MEDIUM6.5Airangel HSMX Gateway devices through 5.2.04 allow CSRF.
CVE-2021-40504MEDIUM4.9A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 71...
CVE-2021-40503HIGH7.8An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an ...
CVE-2021-40502HIGH8.8SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authen...
CVE-2021-40501HIGH8.1SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authe...
CVE-2021-43562HIGH8.8An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension f...
CVE-2021-43561MEDIUM5.4An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for...
CVE-2021-43523CRITICAL9.6In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers ...
CVE-2021-38887MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from applicatio...
CVE-2021-43136CRITICAL9.8An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now