2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-33044CRITICAL9.8The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by...
CVE-2021-40862HIGH8.8HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to a...
CVE-2021-37913CRITICAL9.8The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interfa...
CVE-2021-37912CRITICAL9.8The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network inte...
CVE-2021-37909CRITICAL9.8WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite t...
CVE-2021-33705HIGH8.1The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server...
CVE-2021-33704HIGH8.8The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that...
CVE-2021-33701CRITICAL9.1DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 201...
CVE-2021-33700HIGH7.8SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstance...
CVE-2021-33698HIGH8.8SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script f...
CVE-2021-33697MEDIUM6.1Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an...
CVE-2021-33696MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode u...
CVE-2021-33695CRITICAL9.1Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation...
CVE-2021-33694MEDIUM4.8SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Admin...
CVE-2021-33693MEDIUM6.8SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malic...
CVE-2021-33692HIGH7.5SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject ...
CVE-2021-33691MEDIUM6.1NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in...
CVE-2021-33690CRITICAL9.9Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo...
CVE-2021-40966MEDIUM5.4A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is ...
CVE-2021-40965HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that a...
CVE-2021-40964MEDIUM6.5A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to ...
CVE-2021-39215HIGH7.5Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the ...
CVE-2021-39205MEDIUM6.1Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cr...
CVE-2021-29773MEDIUM5.4IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modif...
CVE-2021-29750HIGH7.5IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now