2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23047 | MEDIUM | 5.3 | 0.6% | Sep 14, 2021 | On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11... |
| CVE-2021-23041 | MEDIUM | 6.1 | 0.6% | Sep 14, 2021 | On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all ... |
| CVE-2021-20582 | MEDIUM | 5.3 | 0.8% | Sep 14, 2021 | IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information discl... |
| CVE-2021-20569 | MEDIUM | 5.3 | 0.9% | Sep 14, 2021 | IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. I... |
| CVE-2021-20508 | MEDIUM | 4.3 | 0.9% | Sep 14, 2021 | IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed tech... |
| CVE-2021-23053 | MEDIUM | 5.3 | 0.9% | Sep 14, 2021 | On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection fea... |
| CVE-2021-23052 | MEDIUM | 6.1 | 0.6% | Sep 14, 2021 | On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers e... |
| CVE-2021-23051 | HIGH | 7.5 | 0.9% | Sep 14, 2021 | On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) dri... |
| CVE-2021-23050 | HIGH | 7.5 | 0.5% | Sep 14, 2021 | On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on a... |
| CVE-2021-23049 | HIGH | 7.5 | 0.9% | Sep 14, 2021 | On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used o... |
| CVE-2021-23048 | HIGH | 7.5 | 0.9% | Sep 14, 2021 | On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and al... |
| CVE-2021-38177 | HIGH | 7.5 | 3.1% | Sep 14, 2021 | SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthentica... |
| CVE-2021-38176 | HIGH | 8.8 | 1.2% | Sep 14, 2021 | Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT functi... |
| CVE-2021-38175 | MEDIUM | 6.5 | 0.8% | Sep 14, 2021 | SAP Analysis for Microsoft Office - version 2.8, allows an attacker with high privileges to read sensitive data over the... |
| CVE-2021-38174 | MEDIUM | 6.5 | 0.7% | Sep 14, 2021 | When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the ... |
| CVE-2021-38164 | MEDIUM | 5.4 | 0.5% | Sep 14, 2021 | SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, ... |
| CVE-2021-38163 | HIGH | 8.8 | 37.1% | Sep 14, 2021 | SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated... |
| CVE-2021-38162 | CRITICAL | 9.4 | 2.6% | Sep 14, 2021 | SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.... |
| CVE-2021-38150 | MEDIUM | 6.5 | 0.5% | Sep 14, 2021 | When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engi... |
| CVE-2021-37535 | CRITICAL | 9.8 | 1.2% | Sep 14, 2021 | SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not pe... |
| CVE-2021-37532 | MEDIUM | 4.3 | 0.8% | Sep 14, 2021 | SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to director... |
| CVE-2021-37531 | HIGH | 8.8 | 3.1% | Sep 14, 2021 | SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerabili... |
| CVE-2021-36582 | CRITICAL | 9.8 | 1.5% | Sep 14, 2021 | In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to recei... |
| CVE-2021-36581 | CRITICAL | 9.8 | 1.5% | Sep 14, 2021 | Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The... |
| CVE-2021-33688 | MEDIUM | 4.3 | 0.6% | Sep 14, 2021 | SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now