2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27628 | HIGH | 7.5 | 1.5% | Jun 9, 2021 | SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, ... |
| CVE-2021-27627 | MEDIUM | 5.9 | 1.2% | Jun 9, 2021 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr... |
| CVE-2021-27626 | MEDIUM | 5.9 | 1.2% | Jun 9, 2021 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr... |
| CVE-2021-27625 | MEDIUM | 5.9 | 1.2% | Jun 9, 2021 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr... |
| CVE-2021-27624 | MEDIUM | 5.9 | 1.2% | Jun 9, 2021 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr... |
| CVE-2021-27623 | MEDIUM | 5.9 | 0.9% | Jun 9, 2021 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr... |
| CVE-2021-27622 | MEDIUM | 5.9 | 1.2% | Jun 9, 2021 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr... |
| CVE-2021-27621 | MEDIUM | 4.9 | 0.6% | Jun 9, 2021 | Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7... |
| CVE-2021-27620 | MEDIUM | 5.9 | 1.2% | Jun 9, 2021 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retr... |
| CVE-2021-27615 | MEDIUM | 5.4 | 0.6% | Jun 9, 2021 | SAP Manufacturing Execution versions - 15.1, 1.5.2, 15.3, 15.4, does not contain some HTTP security headers in their HTT... |
| CVE-2021-27607 | HIGH | 7.5 | 1.5% | Jun 9, 2021 | SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, ... |
| CVE-2021-27606 | HIGH | 7.5 | 1.5% | Jun 9, 2021 | SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22... |
| CVE-2021-27597 | HIGH | 7.5 | 1.5% | Jun 9, 2021 | SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - ... |
| CVE-2021-21490 | MEDIUM | 6.1 | 0.6% | Jun 9, 2021 | SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not suffi... |
| CVE-2021-21473 | MEDIUM | 6.3 | 1.2% | Jun 9, 2021 | SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, con... |
| CVE-2021-33668 | HIGH | 7.5 | 1.1% | Jun 9, 2021 | Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This coul... |
| CVE-2021-3533 | — | — | — | Jun 9, 2021 | Rejected reason: This vulnerability does not meet the criteria for a security vulnerability |
| CVE-2021-3532 | — | — | — | Jun 9, 2021 | Rejected reason: This CVE is marked as INVALID and not a bug |
| CVE-2021-34370 | MEDIUM | 6.1 | 10.0% | Jun 9, 2021 | Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are ... |
| CVE-2021-34369 | MEDIUM | 6.5 | 8.2% | Jun 9, 2021 | portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti... |
| CVE-2021-33842 | HIGH | 8.8 | 0.4% | Jun 9, 2021 | Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an ... |
| CVE-2021-33841 | CRITICAL | 9.8 | 2.2% | Jun 9, 2021 | SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker ... |
| CVE-2021-33829 | MEDIUM | 6.1 | 3.2% | Jun 9, 2021 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 ... |
| CVE-2021-26314 | MEDIUM | 5.5 | 0.6% | Jun 9, 2021 | Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities rel... |
| CVE-2021-26313 | MEDIUM | 5.5 | 0.3% | Jun 9, 2021 | Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities rela... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now