2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29934 | HIGH | 7.3 | 0.9% | Apr 1, 2021 | An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rust. Attackers can read the contents of un... |
| CVE-2021-29933 | HIGH | 7.5 | 1.1% | Apr 1, 2021 | An issue was discovered in the insert_many crate through 2021-01-26 for Rust. Elements may be dropped twice if a .next()... |
| CVE-2021-29932 | HIGH | 7.5 | 1.0% | Apr 1, 2021 | An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial o... |
| CVE-2021-29931 | HIGH | 7.5 | 1.0% | Apr 1, 2021 | An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A double drop can sometimes occur upon a pani... |
| CVE-2021-29930 | HIGH | 7.5 | 1.1% | Apr 1, 2021 | An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A drop of uninitialized memory can sometimes ... |
| CVE-2021-29929 | HIGH | 7.5 | 1.1% | Apr 1, 2021 | An issue was discovered in the endian_trait crate through 2021-01-04 for Rust. A double drop can occur when a user-provi... |
| CVE-2021-29251 | MEDIUM | 6.5 | 0.8% | Apr 1, 2021 | BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). ... |
| CVE-2021-26071 | LOW | 3.5 | 0.5% | Apr 1, 2021 | The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before vers... |
| CVE-2021-29349 | MEDIUM | 6.5 | 1.5% | Mar 31, 2021 | Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the ... |
| CVE-2021-28994 | HIGH | 7.5 | 2.0% | Mar 31, 2021 | kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and ... |
| CVE-2021-27349 | MEDIUM | 6.1 | 0.8% | Mar 31, 2021 | Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727. |
| CVE-2021-27220 | MEDIUM | 5.3 | 2.0% | Mar 31, 2021 | An issue was discovered in PRTG Network Monitor before 21.1.66.1623. By invoking the screenshot functionality with prepa... |
| CVE-2021-22538 | HIGH | 8.8 | 0.7% | Mar 31, 2021 | A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0... |
| CVE-2021-29663 | MEDIUM | 4.8 | 0.8% | Mar 31, 2021 | CourseMS (aka Course Registration Management System) 2.1 is affected by cross-site scripting (XSS). When an attacker wit... |
| CVE-2021-26943 | HIGH | 8.2 | 0.9% | Mar 31, 2021 | The UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary... |
| CVE-2021-29662 | HIGH | 7.5 | 2.2% | Mar 31, 2021 | The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginni... |
| CVE-2021-23007 | MEDIUM | 5.3 | 1.6% | Mar 31, 2021 | On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclose... |
| CVE-2021-23006 | MEDIUM | 6.1 | 0.6% | Mar 31, 2021 | On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerabili... |
| CVE-2021-23005 | CRITICAL | 9.1 | 1.0% | Mar 31, 2021 | On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic... |
| CVE-2021-23004 | HIGH | 7.5 | 1.0% | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x ... |
| CVE-2021-23003 | HIGH | 7.5 | 1.0% | Mar 31, 2021 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x ... |
| CVE-2021-23002 | MEDIUM | 4.5 | 0.3% | Mar 31, 2021 | When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or a... |
| CVE-2021-23001 | MEDIUM | 4.3 | 0.6% | Mar 31, 2021 | On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before ... |
| CVE-2021-23000 | HIGH | 7.5 | 0.9% | Mar 31, 2021 | On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enabled in a BIG-IP syst... |
| CVE-2021-22999 | HIGH | 7.5 | 1.0% | Mar 31, 2021 | On versions 15.0.x before 15.1.0 and 14.1.x before 14.1.4, the BIG-IP system provides an option to connect HTTP/2 client... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now