2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26416HIGH7.7Windows Hyper-V Denial of Service Vulnerability
CVE-2021-26415HIGH7.8Windows Installer Elevation of Privilege Vulnerability
CVE-2021-26413MEDIUM6.2Windows Installer Spoofing Vulnerability
CVE-2021-23372HIGH7.5All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CS...
CVE-2021-21399HIGH7.5Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated...
CVE-2021-27609MEDIUM6.5SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allo...
CVE-2021-27605MEDIUM4.3SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authe...
CVE-2021-27603MEDIUM6.5An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work...
CVE-2021-27602CRITICAL9.9SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create ...
CVE-2021-27601MEDIUM5.4SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicio...
CVE-2021-27600MEDIUM5.4SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed ma...
CVE-2021-27598MEDIUM5.3SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read som...
CVE-2021-23281CRITICAL10Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability...
CVE-2021-23280CRITICAL9.9Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. ...
CVE-2021-23279CRITICAL10Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability...
CVE-2021-23278CRITICAL9.6Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability i...
CVE-2021-23277CRITICAL10Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The s...
CVE-2021-23276HIGH8.8Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can s...
CVE-2021-22720HIGH7.2A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus T...
CVE-2021-22719HIGH8.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus T...
CVE-2021-22718HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus T...
CVE-2021-22717HIGH8.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus T...
CVE-2021-22716HIGH7.8A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execu...
CVE-2021-21784HIGH7.8An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specia...
CVE-2021-21492MEDIUM4.3SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not suffi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now