2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27614 | HIGH | 7.1 | 0.3% | May 11, 2021 | SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP ... |
| CVE-2021-27613 | HIGH | 7.8 | 0.3% | May 11, 2021 | Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, al... |
| CVE-2021-27612 | MEDIUM | 6.1 | 0.6% | May 11, 2021 | In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious... |
| CVE-2021-27611 | MEDIUM | 6.7 | 0.3% | May 11, 2021 | SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by ... |
| CVE-2021-21656 | HIGH | 7.1 | 1.5% | May 11, 2021 | Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XX... |
| CVE-2021-21655 | HIGH | 7.1 | 0.5% | May 11, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to... |
| CVE-2021-21654 | MEDIUM | 4.3 | 1.3% | May 11, 2021 | Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers w... |
| CVE-2021-21653 | MEDIUM | 4.3 | 0.9% | May 11, 2021 | Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint... |
| CVE-2021-21652 | HIGH | 7.1 | 0.6% | May 11, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier al... |
| CVE-2021-21651 | MEDIUM | 4.3 | 0.7% | May 11, 2021 | Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attacke... |
| CVE-2021-21650 | MEDIUM | 4.3 | 0.7% | May 11, 2021 | Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoint... |
| CVE-2021-21649 | MEDIUM | 5.4 | 72.7% | May 11, 2021 | Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in... |
| CVE-2021-21648 | MEDIUM | 6.1 | 11.3% | May 11, 2021 | Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulti... |
| CVE-2021-32561 | MEDIUM | 6.1 | 1.1% | May 11, 2021 | OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters. |
| CVE-2021-32560 | MEDIUM | 6.5 | 1.5% | May 11, 2021 | The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that ar... |
| CVE-2021-21990 | MEDIUM | 6.1 | 0.8% | May 11, 2021 | VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior ... |
| CVE-2021-31915 | CRITICAL | 9.8 | 3.2% | May 11, 2021 | In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. |
| CVE-2021-31914 | CRITICAL | 9.8 | 2.3% | May 11, 2021 | In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. |
| CVE-2021-31913 | HIGH | 7.5 | 0.7% | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchang... |
| CVE-2021-31912 | HIGH | 8.8 | 1.2% | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. |
| CVE-2021-31911 | MEDIUM | 6.1 | 0.7% | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. |
| CVE-2021-31910 | HIGH | 7.5 | 1.3% | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. |
| CVE-2021-31898 | HIGH | 7.5 | 0.6% | May 11, 2021 | In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. |
| CVE-2021-31897 | CRITICAL | 9.8 | 1.5% | May 11, 2021 | In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects. |
| CVE-2021-30482 | HIGH | 7.5 | 0.9% | May 11, 2021 | In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now