2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33044 | CRITICAL | 9.8 | 99.9% | Sep 15, 2021 | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by... |
| CVE-2021-40862 | HIGH | 8.8 | 0.9% | Sep 15, 2021 | HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to a... |
| CVE-2021-37913 | CRITICAL | 9.8 | 2.8% | Sep 15, 2021 | The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interfa... |
| CVE-2021-37912 | CRITICAL | 9.8 | 2.8% | Sep 15, 2021 | The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network inte... |
| CVE-2021-37909 | CRITICAL | 9.8 | 1.9% | Sep 15, 2021 | WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite t... |
| CVE-2021-33705 | HIGH | 8.1 | 2.0% | Sep 15, 2021 | The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server... |
| CVE-2021-33704 | HIGH | 8.8 | 0.6% | Sep 15, 2021 | The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that... |
| CVE-2021-33701 | CRITICAL | 9.1 | 2.0% | Sep 15, 2021 | DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 201... |
| CVE-2021-33700 | HIGH | 7.8 | 0.2% | Sep 15, 2021 | SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstance... |
| CVE-2021-33698 | HIGH | 8.8 | 1.1% | Sep 15, 2021 | SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script f... |
| CVE-2021-33697 | MEDIUM | 6.1 | 0.6% | Sep 15, 2021 | Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an... |
| CVE-2021-33696 | MEDIUM | 5.4 | 0.5% | Sep 15, 2021 | SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode u... |
| CVE-2021-33695 | CRITICAL | 9.1 | 0.5% | Sep 15, 2021 | Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation... |
| CVE-2021-33694 | MEDIUM | 4.8 | 0.4% | Sep 15, 2021 | SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Admin... |
| CVE-2021-33693 | MEDIUM | 6.8 | 0.5% | Sep 15, 2021 | SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malic... |
| CVE-2021-33692 | HIGH | 7.5 | 1.1% | Sep 15, 2021 | SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject ... |
| CVE-2021-33691 | MEDIUM | 6.1 | 0.6% | Sep 15, 2021 | NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in... |
| CVE-2021-33690 | CRITICAL | 9.9 | 67.7% | Sep 15, 2021 | Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo... |
| CVE-2021-40966 | MEDIUM | 5.4 | 0.5% | Sep 15, 2021 | A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is ... |
| CVE-2021-40965 | HIGH | 8.8 | 0.6% | Sep 15, 2021 | A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that a... |
| CVE-2021-40964 | MEDIUM | 6.5 | 8.2% | Sep 15, 2021 | A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to ... |
| CVE-2021-39215 | HIGH | 7.5 | 1.2% | Sep 15, 2021 | Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the ... |
| CVE-2021-39205 | MEDIUM | 6.1 | 1.2% | Sep 15, 2021 | Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cr... |
| CVE-2021-29773 | MEDIUM | 5.4 | 0.7% | Sep 15, 2021 | IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modif... |
| CVE-2021-29750 | HIGH | 7.5 | 0.7% | Sep 15, 2021 | IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now