2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20483 | MEDIUM | 6.5 | 0.9% | Jun 16, 2021 | IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted ... |
| CVE-2021-34803 | HIGH | 7.8 | 0.5% | Jun 16, 2021 | TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations. |
| CVE-2021-34801 | MEDIUM | 5.3 | 1.7% | Jun 16, 2021 | Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agen... |
| CVE-2021-27610 | CRITICAL | 9.8 | 1.6% | Jun 16, 2021 | SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does... |
| CVE-2021-22914 | HIGH | 7.5 | 1.1% | Jun 16, 2021 | Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive infor... |
| CVE-2021-21668 | MEDIUM | 5.4 | 76.0% | Jun 16, 2021 | Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS... |
| CVE-2021-21667 | MEDIUM | 5.4 | 75.7% | Jun 16, 2021 | Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in ... |
| CVE-2021-32928 | CRITICAL | 9.8 | 1.3% | Jun 16, 2021 | The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Ma... |
| CVE-2021-31857 | MEDIUM | 5.9 | 2.7% | Jun 16, 2021 | In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a brow... |
| CVE-2021-31159 | MEDIUM | 5.3 | 17.8% | Jun 16, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag... |
| CVE-2021-27485 | HIGH | 7.5 | 1.2% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable form... |
| CVE-2021-27483 | HIGH | 7.8 | 0.2% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could al... |
| CVE-2021-27479 | MEDIUM | 5.4 | 0.5% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to ... |
| CVE-2021-34683 | MEDIUM | 5.3 | 1.1% | Jun 16, 2021 | An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/... |
| CVE-2021-33813 | HIGH | 7.5 | 19.4% | Jun 16, 2021 | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP reques... |
| CVE-2021-32612 | HIGH | 8.1 | 1.1% | Jun 16, 2021 | The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cl... |
| CVE-2021-32033 | MEDIUM | 4.6 | 0.5% | Jun 16, 2021 | Protectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in cert... |
| CVE-2021-30468 | HIGH | 7.5 | 7.0% | Jun 16, 2021 | A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web serv... |
| CVE-2021-28979 | MEDIUM | 6.5 | 1.4% | Jun 16, 2021 | SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could ex... |
| CVE-2021-27489 | HIGH | 8.8 | 1.3% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious... |
| CVE-2021-27487 | MEDIUM | 5.5 | 0.2% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could ... |
| CVE-2021-27481 | MEDIUM | 5.5 | 0.2% | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange proce... |
| CVE-2021-20094 | HIGH | 7.5 | 4.7% | Jun 16, 2021 | A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker ... |
| CVE-2021-20093 | CRITICAL | 9.1 | 33.3% | Jun 16, 2021 | A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker c... |
| CVE-2021-21441 | HIGH | 7.5 | 1.2% | Jun 16, 2021 | There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now