2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3064 | CRITICAL | 9.8 | 19.1% | Nov 10, 2021 | A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables ... |
| CVE-2021-3063 | HIGH | 7.5 | 0.9% | Nov 10, 2021 | An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gatew... |
| CVE-2021-3062 | HIGH | 8.8 | 0.7% | Nov 10, 2021 | An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProte... |
| CVE-2021-3061 | HIGH | 7.2 | 0.9% | Nov 10, 2021 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authentic... |
| CVE-2021-3060 | HIGH | 8.1 | 33.9% | Nov 10, 2021 | An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software al... |
| CVE-2021-3059 | HIGH | 8.1 | 1.5% | Nov 10, 2021 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynam... |
| CVE-2021-3058 | HIGH | 7.2 | 1.6% | Nov 10, 2021 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administra... |
| CVE-2021-3056 | HIGH | 8.8 | 1.5% | Nov 10, 2021 | A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated att... |
| CVE-2021-43564 | HIGH | 7.5 | 1.0% | Nov 10, 2021 | An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extens... |
| CVE-2021-43563 | HIGH | 8.8 | 1.0% | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Cont... |
| CVE-2021-42062 | MEDIUM | 4.3 | 0.6% | Nov 10, 2021 | SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employe... |
| CVE-2021-41427 | MEDIUM | 6.1 | 1.0% | Nov 10, 2021 | Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi. |
| CVE-2021-41426 | HIGH | 8.8 | 0.7% | Nov 10, 2021 | Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm. |
| CVE-2021-40521 | CRITICAL | 9.8 | 4.3% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 allow Remote Code Execution. |
| CVE-2021-40519 | CRITICAL | 10 | 1.1% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials. |
| CVE-2021-40518 | MEDIUM | 6.5 | 0.4% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 allow CSRF. |
| CVE-2021-40504 | MEDIUM | 4.9 | 0.6% | Nov 10, 2021 | A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 71... |
| CVE-2021-40503 | HIGH | 7.8 | 0.2% | Nov 10, 2021 | An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an ... |
| CVE-2021-40502 | HIGH | 8.8 | 0.8% | Nov 10, 2021 | SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authen... |
| CVE-2021-40501 | HIGH | 8.1 | 0.7% | Nov 10, 2021 | SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authe... |
| CVE-2021-43562 | HIGH | 8.8 | 1.3% | Nov 10, 2021 | An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension f... |
| CVE-2021-43561 | MEDIUM | 5.4 | 0.5% | Nov 10, 2021 | An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for... |
| CVE-2021-43523 | CRITICAL | 9.6 | 3.3% | Nov 10, 2021 | In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers ... |
| CVE-2021-38887 | MEDIUM | 6.5 | 0.8% | Nov 10, 2021 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from applicatio... |
| CVE-2021-43136 | CRITICAL | 9.8 | 15.7% | Nov 10, 2021 | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now