2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23004 | HIGH | 7.5 | 1.0% | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x ... |
| CVE-2021-23003 | HIGH | 7.5 | 1.0% | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x ... |
| CVE-2021-23000 | HIGH | 7.5 | 0.9% | Mar 31, 2021 | On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enabled in a BIG-IP syst... |
| CVE-2021-22999 | HIGH | 7.5 | 1.0% | Mar 31, 2021 | On versions 15.0.x before 15.1.0 and 14.1.x before 14.1.4, the BIG-IP system provides an option to connect HTTP/2 client... |
| CVE-2021-22997 | HIGH | 7.5 | 1.1% | Mar 31, 2021 | On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authenticat... |
| CVE-2021-22996 | HIGH | 7.5 | 1.0% | Mar 31, 2021 | On all 7.x versions (fixed in 8.0.0), when set up for auto failover, a BIG-IQ Data Collection Device (DCD) cluster membe... |
| CVE-2021-22993 | HIGH | 8.8 | 0.9% | Mar 31, 2021 | On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.... |
| CVE-2021-21975 | HIGH | 7.5 | 78.3% | Mar 31, 2021 | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor... |
| CVE-2021-29658 | HIGH | 8.8 | 1.2% | Mar 31, 2021 | The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries ... |
| CVE-2021-22995 | HIGH | 7.5 | 0.9% | Mar 31, 2021 | On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic fai... |
| CVE-2021-22990 | HIGH | 7.2 | 8.8% | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x ... |
| CVE-2021-23348 | HIGH | 8.8 | 1.8% | Mar 31, 2021 | This affects the package portprocesses before 1.0.5. If (attacker-controlled) user input is given to the killProcess fun... |
| CVE-2021-22988 | HIGH | 8.8 | 10.4% | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x ... |
| CVE-2021-28245 | HIGH | 7.5 | 1.1% | Mar 31, 2021 | PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensiti... |
| CVE-2021-23988 | HIGH | 8.8 | 1.1% | Mar 31, 2021 | Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corru... |
| CVE-2021-23987 | HIGH | 8.8 | 1.4% | Mar 31, 2021 | Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of... |
| CVE-2021-23981 | HIGH | 8.1 | 1.1% | Mar 31, 2021 | A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack i... |
| CVE-2021-21782 | HIGH | 8.8 | 1.3% | Mar 31, 2021 | An out-of-bounds write vulnerability exists in the SGI format buffer size processing functionality of Accusoft ImageGear... |
| CVE-2021-21776 | HIGH | 8.8 | 1.3% | Mar 31, 2021 | An out-of-bounds write vulnerability exists in the SGI Format Buffer Size Processing functionality of Accusoft ImageGear... |
| CVE-2021-21773 | HIGH | 7.8 | 0.7% | Mar 31, 2021 | An out-of-bounds write vulnerability exists in the TIFF header count-processing functionality of Accusoft ImageGear 19.8... |
| CVE-2021-21412 | HIGH | 8.8 | 1.3% | Mar 30, 2021 | Potential for arbitrary code execution in npm package @thi.ng/egf `#gpg`-tagged property values (only if `decrypt: true`... |
| CVE-2021-20502 | HIGH | 7.1 | 1.4% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A... |
| CVE-2021-20482 | HIGH | 7.1 | 1.4% | Mar 30, 2021 | IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack whe... |
| CVE-2021-27271 | HIGH | 7.8 | 3.3% | Mar 30, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.... |
| CVE-2021-27270 | HIGH | 7.8 | 2.7% | Mar 30, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now