2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-33583CRITICAL9.8REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.
CVE-2021-41288CRITICAL9.8Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
CVE-2021-20578CRITICAL9.8IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized...
CVE-2021-41729CRITICAL9.1BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrar...
CVE-2021-41301CRITICAL9.8ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files...
CVE-2021-41300CRITICAL9.8ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can...
CVE-2021-41299CRITICAL9.8ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers c...
CVE-2021-41296CRITICAL9.8ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password at...
CVE-2021-41294CRITICAL9.1ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GE...
CVE-2021-41292CRITICAL9.1ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie pois...
CVE-2021-41290CRITICAL9.8ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, un...
CVE-2021-41616CRITICAL9.8Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL ...
CVE-2021-35943CRITICAL9.8Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented ...
CVE-2021-36745CRITICAL9.8A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Netwo...
CVE-2021-33924CRITICAL9.8Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its a...
CVE-2021-38303CRITICAL9.8A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360.
CVE-2021-36366CRITICAL9.8Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.
CVE-2021-36365CRITICAL9.8Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
CVE-2021-36364CRITICAL9.8Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.
CVE-2021-36363CRITICAL9.8Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
CVE-2021-38124CRITICAL9.8Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting version...
CVE-2021-37270CRITICAL9.8There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use t...
CVE-2021-20034CRITICAL9.1An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal...
CVE-2021-41558CRITICAL9.8The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config.
CVE-2021-40329CRITICAL9.8The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password managem...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now