2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38195CRITICAL9.8An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it a...
CVE-2021-38194CRITICAL9.8An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the Fiel...
CVE-2021-38193MEDIUM6.1An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HT...
CVE-2021-38192HIGH7.5An issue was discovered in the prost-types crate before 0.8.0 for Rust. An overflow can occur during conversion from Tim...
CVE-2021-38191MEDIUM5.9An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the...
CVE-2021-38190CRITICAL9.8An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it d...
CVE-2021-38189CRITICAL9.8An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . ...
CVE-2021-38188CRITICAL9.8An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. In Decoder::new(), slice.get_unchecked(slice.leng...
CVE-2021-38187CRITICAL9.8An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a ...
CVE-2021-38186MEDIUM6.1An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HT...
CVE-2021-36221MEDIUM5.9Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic ...
CVE-2021-38185HIGH7.8GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_f...
CVE-2021-38173CRITICAL9.8Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh...
CVE-2021-38169HIGH8.8Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
CVE-2021-38168HIGH8.8Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.
CVE-2021-38167CRITICAL9.8Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to by...
CVE-2021-38166HIGH7.8In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when ma...
CVE-2021-38165MEDIUM5.3Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext cr...
CVE-2021-38159CRITICAL9.8In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web appl...
CVE-2021-29923HIGH7.5Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in ...
CVE-2021-29922CRITICAL9.1library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginni...
CVE-2021-38160HIGH7.8In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untru...
CVE-2021-38148CRITICAL9.8Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.
CVE-2021-38157MEDIUM6.1LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. N...
CVE-2021-38155HIGH7.5OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allow...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now