2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23047MEDIUM5.3On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11...
CVE-2021-23041MEDIUM6.1On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all ...
CVE-2021-20582MEDIUM5.3IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information discl...
CVE-2021-20569MEDIUM5.3IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. I...
CVE-2021-20508MEDIUM4.3IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed tech...
CVE-2021-23053MEDIUM5.3On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection fea...
CVE-2021-23052MEDIUM6.1On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers e...
CVE-2021-23051HIGH7.5On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) dri...
CVE-2021-23050HIGH7.5On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on a...
CVE-2021-23049HIGH7.5On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used o...
CVE-2021-23048HIGH7.5On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and al...
CVE-2021-38177HIGH7.5SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthentica...
CVE-2021-38176HIGH8.8Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT functi...
CVE-2021-38175MEDIUM6.5SAP Analysis for Microsoft Office - version 2.8, allows an attacker with high privileges to read sensitive data over the...
CVE-2021-38174MEDIUM6.5When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the ...
CVE-2021-38164MEDIUM5.4SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, ...
CVE-2021-38163HIGH8.8SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated...
CVE-2021-38162CRITICAL9.4SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7....
CVE-2021-38150MEDIUM6.5When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engi...
CVE-2021-37535CRITICAL9.8SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not pe...
CVE-2021-37532MEDIUM4.3SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to director...
CVE-2021-37531HIGH8.8SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerabili...
CVE-2021-36582CRITICAL9.8In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to recei...
CVE-2021-36581CRITICAL9.8Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The...
CVE-2021-33688MEDIUM4.3SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now