2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33583 | CRITICAL | 9.8 | 1.2% | Sep 30, 2021 | REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file. |
| CVE-2021-41288 | CRITICAL | 9.8 | 79.6% | Sep 30, 2021 | Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API. |
| CVE-2021-20578 | CRITICAL | 9.8 | 1.0% | Sep 30, 2021 | IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized... |
| CVE-2021-41729 | CRITICAL | 9.1 | 1.0% | Sep 30, 2021 | BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrar... |
| CVE-2021-41301 | CRITICAL | 9.8 | 1.9% | Sep 30, 2021 | ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files... |
| CVE-2021-41300 | CRITICAL | 9.8 | 0.9% | Sep 30, 2021 | ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can... |
| CVE-2021-41299 | CRITICAL | 9.8 | 2.0% | Sep 30, 2021 | ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers c... |
| CVE-2021-41296 | CRITICAL | 9.8 | 0.9% | Sep 30, 2021 | ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password at... |
| CVE-2021-41294 | CRITICAL | 9.1 | 1.1% | Sep 30, 2021 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GE... |
| CVE-2021-41292 | CRITICAL | 9.1 | 1.1% | Sep 30, 2021 | ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie pois... |
| CVE-2021-41290 | CRITICAL | 9.8 | 2.2% | Sep 30, 2021 | ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, un... |
| CVE-2021-41616 | CRITICAL | 9.8 | 3.2% | Sep 30, 2021 | Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL ... |
| CVE-2021-35943 | CRITICAL | 9.8 | 1.0% | Sep 29, 2021 | Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented ... |
| CVE-2021-36745 | CRITICAL | 9.8 | 9.0% | Sep 29, 2021 | A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Netwo... |
| CVE-2021-33924 | CRITICAL | 9.8 | 1.6% | Sep 29, 2021 | Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its a... |
| CVE-2021-38303 | CRITICAL | 9.8 | 1.3% | Sep 28, 2021 | A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360. |
| CVE-2021-36366 | CRITICAL | 9.8 | 3.9% | Sep 28, 2021 | Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards. |
| CVE-2021-36365 | CRITICAL | 9.8 | 3.7% | Sep 28, 2021 | Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh. |
| CVE-2021-36364 | CRITICAL | 9.8 | 3.9% | Sep 28, 2021 | Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards. |
| CVE-2021-36363 | CRITICAL | 9.8 | 3.7% | Sep 28, 2021 | Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php. |
| CVE-2021-38124 | CRITICAL | 9.8 | 2.0% | Sep 28, 2021 | Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting version... |
| CVE-2021-37270 | CRITICAL | 9.8 | 1.4% | Sep 27, 2021 | There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use t... |
| CVE-2021-20034 | CRITICAL | 9.1 | 80.7% | Sep 27, 2021 | An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal... |
| CVE-2021-41558 | CRITICAL | 9.8 | 1.2% | Sep 27, 2021 | The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config. |
| CVE-2021-40329 | CRITICAL | 9.8 | 1.1% | Sep 27, 2021 | The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password managem... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now