2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27628HIGH7.5SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, ...
CVE-2021-27627MEDIUM5.9SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr...
CVE-2021-27626MEDIUM5.9SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr...
CVE-2021-27625MEDIUM5.9SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr...
CVE-2021-27624MEDIUM5.9SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr...
CVE-2021-27623MEDIUM5.9SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr...
CVE-2021-27622MEDIUM5.9SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr...
CVE-2021-27621MEDIUM4.9Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7...
CVE-2021-27620MEDIUM5.9SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr...
CVE-2021-27615MEDIUM5.4SAP Manufacturing Execution versions - 15.1, 1.5.2, 15.3, 15.4, does not contain some HTTP security headers in their HTT...
CVE-2021-27607HIGH7.5SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, ...
CVE-2021-27606HIGH7.5SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22...
CVE-2021-27597HIGH7.5SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - ...
CVE-2021-21490MEDIUM6.1SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not suffi...
CVE-2021-21473MEDIUM6.3SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, con...
CVE-2021-33668HIGH7.5Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This coul...
CVE-2021-3533Rejected reason: This vulnerability does not meet the criteria for a security vulnerability
CVE-2021-3532Rejected reason: This CVE is marked as INVALID and not a bug
CVE-2021-34370MEDIUM6.1Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are ...
CVE-2021-34369MEDIUM6.5portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti...
CVE-2021-33842HIGH8.8Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an ...
CVE-2021-33841CRITICAL9.8SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker ...
CVE-2021-33829MEDIUM6.1A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 ...
CVE-2021-26314MEDIUM5.5Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities rel...
CVE-2021-26313MEDIUM5.5Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities rela...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now