2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33676 | HIGH | 7.2 | 0.9% | Jul 14, 2021 | A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with hi... |
| CVE-2021-33671 | HIGH | 8.8 | 0.7% | Jul 14, 2021 | SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perfor... |
| CVE-2021-33670 | HIGH | 7.5 | 3.2% | Jul 14, 2021 | SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows ... |
| CVE-2021-33667 | MEDIUM | 4.3 | 0.7% | Jul 14, 2021 | Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker t... |
| CVE-2021-25953 | CRITICAL | 9.8 | 3.0% | Jul 14, 2021 | Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of serv... |
| CVE-2021-22318 | MEDIUM | 5.5 | 0.1% | Jul 14, 2021 | A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerab... |
| CVE-2021-36374 | MEDIUM | 5.5 | 2.6% | Jul 14, 2021 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large am... |
| CVE-2021-36373 | MEDIUM | 5.5 | 2.5% | Jul 14, 2021 | When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that fi... |
| CVE-2021-20784 | MEDIUM | 6.1 | 1.1% | Jul 14, 2021 | HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote a... |
| CVE-2021-20782 | HIGH | 8.8 | 0.9% | Jul 14, 2021 | Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attack... |
| CVE-2021-20781 | HIGH | 8.8 | 0.8% | Jul 14, 2021 | Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.... |
| CVE-2021-20748 | HIGH | 7.5 | 1.0% | Jul 14, 2021 | Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key... |
| CVE-2021-20747 | MEDIUM | 4.3 | 1.0% | Jul 14, 2021 | Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 ... |
| CVE-2021-32755 | MEDIUM | 4.3 | 0.3% | Jul 13, 2021 | Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries f... |
| CVE-2021-22000 | HIGH | 7.8 | 0.6% | Jul 13, 2021 | VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A mali... |
| CVE-2021-21995 | HIGH | 7.5 | 1.0% | Jul 13, 2021 | OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor wit... |
| CVE-2021-21994 | CRITICAL | 9.8 | 1.2% | Jul 13, 2021 | SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with net... |
| CVE-2021-36214 | MEDIUM | 6.1 | 0.7% | Jul 13, 2021 | LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView. |
| CVE-2021-31217 | CRITICAL | 9.1 | 3.8% | Jul 13, 2021 | In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. |
| CVE-2021-34552 | CRITICAL | 9.8 | 3.2% | Jul 13, 2021 | Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters ... |
| CVE-2021-20424 | MEDIUM | 4.3 | 1.0% | Jul 13, 2021 | IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technic... |
| CVE-2021-20423 | HIGH | 8.8 | 1.1% | Jul 13, 2021 | IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper applicat... |
| CVE-2021-20422 | HIGH | 7.5 | 1.3% | Jul 13, 2021 | IBM Cloud Pak for Applications 4.3 could disclose sensitive information to a malicious attacker by accessing data stored... |
| CVE-2021-20369 | MEDIUM | 5.9 | 0.7% | Jul 13, 2021 | IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to de... |
| CVE-2021-20368 | MEDIUM | 5.4 | 0.5% | Jul 13, 2021 | IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now