2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21430 | MEDIUM | 5.5 | 0.4% | May 10, 2021 | OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configurat... |
| CVE-2021-29022 | MEDIUM | 5.3 | 1.0% | May 10, 2021 | In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory. |
| CVE-2021-21428 | HIGH | 7 | 0.4% | May 10, 2021 | Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documen... |
| CVE-2021-29502 | MEDIUM | 6.5 | 0.8% | May 10, 2021 | WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to... |
| CVE-2021-29501 | MEDIUM | 6.5 | 0.9% | May 10, 2021 | Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users t... |
| CVE-2021-20577 | MEDIUM | 6.1 | 0.6% | May 10, 2021 | IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2021-20559 | MEDIUM | 5.4 | 0.5% | May 10, 2021 | IBM Control Desk 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2021-20538 | CRITICAL | 9.1 | 0.7% | May 10, 2021 | IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform acti... |
| CVE-2021-31877 | — | — | — | May 10, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due... |
| CVE-2021-21822 | HIGH | 8.8 | 1.8% | May 10, 2021 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A s... |
| CVE-2021-28664 | HIGH | 8.8 | 5.5% | May 10, 2021 | The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivi... |
| CVE-2021-28663 | HIGH | 8.8 | 12.1% | May 10, 2021 | The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are m... |
| CVE-2021-23016 | MEDIUM | 5.3 | 0.8% | May 10, 2021 | On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 1... |
| CVE-2021-23015 | HIGH | 7.2 | 1.3% | May 10, 2021 | On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when runn... |
| CVE-2021-23014 | HIGH | 8.8 | 0.8% | May 10, 2021 | On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are miss... |
| CVE-2021-23012 | HIGH | 8.2 | 0.3% | May 10, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of... |
| CVE-2021-23010 | HIGH | 7.5 | 1.0% | May 10, 2021 | On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and 12.1.x bef... |
| CVE-2021-23009 | HIGH | 7.5 | 1.0% | May 10, 2021 | On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop ... |
| CVE-2021-32056 | MEDIUM | 4.3 | 1.7% | May 10, 2021 | Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access r... |
| CVE-2021-23013 | HIGH | 7.5 | 0.9% | May 10, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.... |
| CVE-2021-23011 | HIGH | 7.5 | 1.0% | May 10, 2021 | On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1... |
| CVE-2021-23008 | CRITICAL | 9.8 | 1.3% | May 10, 2021 | On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 1... |
| CVE-2021-26583 | CRITICAL | 9.8 | 4.4% | May 10, 2021 | A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely explo... |
| CVE-2021-25645 | MEDIUM | 4.4 | 0.2% | May 10, 2021 | An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An i... |
| CVE-2021-22672 | HIGH | 7.8 | 9.7% | May 10, 2021 | Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-se... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now