2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20483MEDIUM6.5IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted ...
CVE-2021-34803HIGH7.8TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
CVE-2021-34801MEDIUM5.3Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agen...
CVE-2021-27610CRITICAL9.8SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does...
CVE-2021-22914HIGH7.5Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive infor...
CVE-2021-21668MEDIUM5.4Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS...
CVE-2021-21667MEDIUM5.4Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in ...
CVE-2021-32928CRITICAL9.8The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Ma...
CVE-2021-31857MEDIUM5.9In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a brow...
CVE-2021-31159MEDIUM5.3Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag...
CVE-2021-27485HIGH7.5ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable form...
CVE-2021-27483HIGH7.8ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could al...
CVE-2021-27479MEDIUM5.4ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to ...
CVE-2021-34683MEDIUM5.3An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/...
CVE-2021-33813HIGH7.5An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP reques...
CVE-2021-32612HIGH8.1The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cl...
CVE-2021-32033MEDIUM4.6Protectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in cert...
CVE-2021-30468HIGH7.5A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web serv...
CVE-2021-28979MEDIUM6.5SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could ex...
CVE-2021-27489HIGH8.8ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious...
CVE-2021-27487MEDIUM5.5ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could ...
CVE-2021-27481MEDIUM5.5ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange proce...
CVE-2021-20094HIGH7.5A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker ...
CVE-2021-20093CRITICAL9.1A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker c...
CVE-2021-21441HIGH7.5There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now