2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23924 | HIGH | 7.5 | 1.0% | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic... |
| CVE-2021-23923 | HIGH | 8.1 | 0.8% | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users. |
| CVE-2021-21420 | HIGH | 7.8 | 0.6% | Apr 1, 2021 | vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists ... |
| CVE-2021-29421 | HIGH | 7.5 | 1.7% | Apr 1, 2021 | models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries. |
| CVE-2021-25924 | HIGH | 8.8 | 0.8% | Apr 1, 2021 | In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/... |
| CVE-2021-22195 | HIGH | 7.8 | 1.1% | Apr 1, 2021 | Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system |
| CVE-2021-28165 | HIGH | 7.5 | 53.9% | Apr 1, 2021 | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon re... |
| CVE-2021-28545 | HIGH | 8.1 | 2.3% | Apr 1, 2021 | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e... |
| CVE-2021-20235 | HIGH | 8.1 | 43.9% | Apr 1, 2021 | There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator... |
| CVE-2021-29083 | HIGH | 7.2 | 2.6% | Apr 1, 2021 | Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Man... |
| CVE-2021-29942 | HIGH | 7.3 | 0.9% | Apr 1, 2021 | An issue was discovered in the reorder crate through 2021-02-24 for Rust. swap_index can return uninitialized values if ... |
| CVE-2021-29941 | HIGH | 7.3 | 0.9% | Apr 1, 2021 | An issue was discovered in the reorder crate through 2021-02-24 for Rust. swap_index has an out-of-bounds write if an it... |
| CVE-2021-29939 | HIGH | 7.3 | 1.0% | Apr 1, 2021 | An issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVe... |
| CVE-2021-29938 | HIGH | 7.5 | 1.1% | Apr 1, 2021 | An issue was discovered in the slice-deque crate through 2021-02-19 for Rust. A double drop can occur in SliceDeque::dra... |
| CVE-2021-29935 | HIGH | 7.3 | 1.0% | Apr 1, 2021 | An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-pr... |
| CVE-2021-29934 | HIGH | 7.3 | 0.9% | Apr 1, 2021 | An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rust. Attackers can read the contents of un... |
| CVE-2021-29933 | HIGH | 7.5 | 1.1% | Apr 1, 2021 | An issue was discovered in the insert_many crate through 2021-01-26 for Rust. Elements may be dropped twice if a .next()... |
| CVE-2021-29932 | HIGH | 7.5 | 1.0% | Apr 1, 2021 | An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial o... |
| CVE-2021-29931 | HIGH | 7.5 | 1.0% | Apr 1, 2021 | An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A double drop can sometimes occur upon a pani... |
| CVE-2021-29930 | HIGH | 7.5 | 1.1% | Apr 1, 2021 | An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A drop of uninitialized memory can sometimes ... |
| CVE-2021-29929 | HIGH | 7.5 | 1.1% | Apr 1, 2021 | An issue was discovered in the endian_trait crate through 2021-01-04 for Rust. A double drop can occur when a user-provi... |
| CVE-2021-28994 | HIGH | 7.5 | 2.0% | Mar 31, 2021 | kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and ... |
| CVE-2021-22538 | HIGH | 8.8 | 0.7% | Mar 31, 2021 | A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0... |
| CVE-2021-26943 | HIGH | 8.2 | 0.9% | Mar 31, 2021 | The UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary... |
| CVE-2021-29662 | HIGH | 7.5 | 2.2% | Mar 31, 2021 | The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginni... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now