2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26416 | HIGH | 7.7 | 3.9% | Apr 13, 2021 | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2021-26415 | HIGH | 7.8 | 3.6% | Apr 13, 2021 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2021-26413 | MEDIUM | 6.2 | 0.7% | Apr 13, 2021 | Windows Installer Spoofing Vulnerability |
| CVE-2021-23372 | HIGH | 7.5 | 0.9% | Apr 13, 2021 | All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CS... |
| CVE-2021-21399 | HIGH | 7.5 | 1.4% | Apr 13, 2021 | Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated... |
| CVE-2021-27609 | MEDIUM | 6.5 | 0.5% | Apr 13, 2021 | SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allo... |
| CVE-2021-27605 | MEDIUM | 4.3 | 0.6% | Apr 13, 2021 | SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authe... |
| CVE-2021-27603 | MEDIUM | 6.5 | 0.9% | Apr 13, 2021 | An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work... |
| CVE-2021-27602 | CRITICAL | 9.9 | 2.0% | Apr 13, 2021 | SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create ... |
| CVE-2021-27601 | MEDIUM | 5.4 | 0.5% | Apr 13, 2021 | SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicio... |
| CVE-2021-27600 | MEDIUM | 5.4 | 0.6% | Apr 13, 2021 | SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed ma... |
| CVE-2021-27598 | MEDIUM | 5.3 | 0.6% | Apr 13, 2021 | SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read som... |
| CVE-2021-23281 | CRITICAL | 10 | 2.2% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability... |
| CVE-2021-23280 | CRITICAL | 9.9 | 0.9% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. ... |
| CVE-2021-23279 | CRITICAL | 10 | 27.1% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability... |
| CVE-2021-23278 | CRITICAL | 9.6 | 1.0% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability i... |
| CVE-2021-23277 | CRITICAL | 10 | 1.0% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The s... |
| CVE-2021-23276 | HIGH | 8.8 | 0.8% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can s... |
| CVE-2021-22720 | HIGH | 7.2 | 30.5% | Apr 13, 2021 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus T... |
| CVE-2021-22719 | HIGH | 8.8 | 40.6% | Apr 13, 2021 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus T... |
| CVE-2021-22718 | HIGH | 7.8 | 27.2% | Apr 13, 2021 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus T... |
| CVE-2021-22717 | HIGH | 8.8 | 38.9% | Apr 13, 2021 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus T... |
| CVE-2021-22716 | HIGH | 7.8 | 0.8% | Apr 13, 2021 | A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execu... |
| CVE-2021-21784 | HIGH | 7.8 | 0.8% | Apr 13, 2021 | An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specia... |
| CVE-2021-21492 | MEDIUM | 4.3 | 0.6% | Apr 13, 2021 | SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not suffi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now