2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-33676HIGH7.2A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with hi...
CVE-2021-33671HIGH8.8SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perfor...
CVE-2021-33670HIGH7.5SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows ...
CVE-2021-33667MEDIUM4.3Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker t...
CVE-2021-25953CRITICAL9.8Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of serv...
CVE-2021-22318MEDIUM5.5A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerab...
CVE-2021-36374MEDIUM5.5When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large am...
CVE-2021-36373MEDIUM5.5When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that fi...
CVE-2021-20784MEDIUM6.1HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote a...
CVE-2021-20782HIGH8.8Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attack...
CVE-2021-20781HIGH8.8Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1....
CVE-2021-20748HIGH7.5Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key...
CVE-2021-20747MEDIUM4.3Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 ...
CVE-2021-32755MEDIUM4.3Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries f...
CVE-2021-22000HIGH7.8VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A mali...
CVE-2021-21995HIGH7.5OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor wit...
CVE-2021-21994CRITICAL9.8SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with net...
CVE-2021-36214MEDIUM6.1LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.
CVE-2021-31217CRITICAL9.1In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
CVE-2021-34552CRITICAL9.8Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters ...
CVE-2021-20424MEDIUM4.3IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technic...
CVE-2021-20423HIGH8.8IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper applicat...
CVE-2021-20422HIGH7.5IBM Cloud Pak for Applications 4.3 could disclose sensitive information to a malicious attacker by accessing data stored...
CVE-2021-20369MEDIUM5.9IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to de...
CVE-2021-20368MEDIUM5.4IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now