2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38195 | CRITICAL | 9.8 | 0.9% | Aug 8, 2021 | An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it a... |
| CVE-2021-38194 | CRITICAL | 9.8 | 1.3% | Aug 8, 2021 | An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the Fiel... |
| CVE-2021-38193 | MEDIUM | 6.1 | 0.7% | Aug 8, 2021 | An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HT... |
| CVE-2021-38192 | HIGH | 7.5 | 1.1% | Aug 8, 2021 | An issue was discovered in the prost-types crate before 0.8.0 for Rust. An overflow can occur during conversion from Tim... |
| CVE-2021-38191 | MEDIUM | 5.9 | 0.8% | Aug 8, 2021 | An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the... |
| CVE-2021-38190 | CRITICAL | 9.8 | 1.4% | Aug 8, 2021 | An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it d... |
| CVE-2021-38189 | CRITICAL | 9.8 | 1.5% | Aug 8, 2021 | An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . ... |
| CVE-2021-38188 | CRITICAL | 9.8 | 1.3% | Aug 8, 2021 | An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. In Decoder::new(), slice.get_unchecked(slice.leng... |
| CVE-2021-38187 | CRITICAL | 9.8 | 1.4% | Aug 8, 2021 | An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a ... |
| CVE-2021-38186 | MEDIUM | 6.1 | 0.7% | Aug 8, 2021 | An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HT... |
| CVE-2021-36221 | MEDIUM | 5.9 | 3.1% | Aug 8, 2021 | Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic ... |
| CVE-2021-38185 | HIGH | 7.8 | 4.2% | Aug 8, 2021 | GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_f... |
| CVE-2021-38173 | CRITICAL | 9.8 | 3.2% | Aug 7, 2021 | Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh... |
| CVE-2021-38169 | HIGH | 8.8 | 1.5% | Aug 7, 2021 | Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py. |
| CVE-2021-38168 | HIGH | 8.8 | 0.9% | Aug 7, 2021 | Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers. |
| CVE-2021-38167 | CRITICAL | 9.8 | 1.3% | Aug 7, 2021 | Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to by... |
| CVE-2021-38166 | HIGH | 7.8 | 0.3% | Aug 7, 2021 | In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when ma... |
| CVE-2021-38165 | MEDIUM | 5.3 | 4.5% | Aug 7, 2021 | Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext cr... |
| CVE-2021-38159 | CRITICAL | 9.8 | 1.9% | Aug 7, 2021 | In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web appl... |
| CVE-2021-29923 | HIGH | 7.5 | 3.7% | Aug 7, 2021 | Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in ... |
| CVE-2021-29922 | CRITICAL | 9.1 | 2.6% | Aug 7, 2021 | library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginni... |
| CVE-2021-38160 | HIGH | 7.8 | 0.4% | Aug 7, 2021 | In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untru... |
| CVE-2021-38148 | CRITICAL | 9.8 | 1.2% | Aug 7, 2021 | Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs. |
| CVE-2021-38157 | MEDIUM | 6.1 | 1.1% | Aug 6, 2021 | LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. N... |
| CVE-2021-38155 | HIGH | 7.5 | 2.5% | Aug 6, 2021 | OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allow... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now