2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-31913HIGH7.5In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchang...
CVE-2021-31912HIGH8.8In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
CVE-2021-31910HIGH7.5In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.
CVE-2021-31898HIGH7.5In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
CVE-2021-30482HIGH7.5In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly
CVE-2021-31905HIGH7.5In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
CVE-2021-31902HIGH7.5In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
CVE-2021-31901HIGH7.5In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
CVE-2021-31899HIGH8.8In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-on...
CVE-2021-30504HIGH7.5In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
CVE-2021-30006HIGH7.5In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
CVE-2021-30005HIGH7.8In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the ...
CVE-2021-29263HIGH7.8In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the p...
CVE-2021-26310HIGH7.5In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
CVE-2021-32399HIGH7net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
CVE-2021-21428HIGH7Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documen...
CVE-2021-21822HIGH8.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A s...
CVE-2021-28664HIGH8.8The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivi...
CVE-2021-28663HIGH8.8The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are m...
CVE-2021-23015HIGH7.2On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when runn...
CVE-2021-23014HIGH8.8On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are miss...
CVE-2021-23012HIGH8.2On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of...
CVE-2021-23010HIGH7.5On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and 12.1.x bef...
CVE-2021-23009HIGH7.5On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop ...
CVE-2021-23013HIGH7.5On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now