2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27614HIGH7.1SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP ...
CVE-2021-27613HIGH7.8Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, al...
CVE-2021-27612MEDIUM6.1In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious...
CVE-2021-27611MEDIUM6.7SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by ...
CVE-2021-21656HIGH7.1Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XX...
CVE-2021-21655HIGH7.1A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to...
CVE-2021-21654MEDIUM4.3Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers w...
CVE-2021-21653MEDIUM4.3Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint...
CVE-2021-21652HIGH7.1A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier al...
CVE-2021-21651MEDIUM4.3Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attacke...
CVE-2021-21650MEDIUM4.3Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoint...
CVE-2021-21649MEDIUM5.4Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in...
CVE-2021-21648MEDIUM6.1Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulti...
CVE-2021-32561MEDIUM6.1OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.
CVE-2021-32560MEDIUM6.5The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that ar...
CVE-2021-21990MEDIUM6.1VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior ...
CVE-2021-31915CRITICAL9.8In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.
CVE-2021-31914CRITICAL9.8In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.
CVE-2021-31913HIGH7.5In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchang...
CVE-2021-31912HIGH8.8In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
CVE-2021-31911MEDIUM6.1In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.
CVE-2021-31910HIGH7.5In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.
CVE-2021-31898HIGH7.5In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
CVE-2021-31897CRITICAL9.8In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.
CVE-2021-30482HIGH7.5In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now