2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29934HIGH7.3An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rust. Attackers can read the contents of un...
CVE-2021-29933HIGH7.5An issue was discovered in the insert_many crate through 2021-01-26 for Rust. Elements may be dropped twice if a .next()...
CVE-2021-29932HIGH7.5An issue was discovered in the parse_duration crate through 2021-03-18 for Rust. It allows attackers to cause a denial o...
CVE-2021-29931HIGH7.5An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A double drop can sometimes occur upon a pani...
CVE-2021-29930HIGH7.5An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A drop of uninitialized memory can sometimes ...
CVE-2021-29929HIGH7.5An issue was discovered in the endian_trait crate through 2021-01-04 for Rust. A double drop can occur when a user-provi...
CVE-2021-29251MEDIUM6.5BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). ...
CVE-2021-26071LOW3.5The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before vers...
CVE-2021-29349MEDIUM6.5Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the ...
CVE-2021-28994HIGH7.5kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and ...
CVE-2021-27349MEDIUM6.1Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727.
CVE-2021-27220MEDIUM5.3An issue was discovered in PRTG Network Monitor before 21.1.66.1623. By invoking the screenshot functionality with prepa...
CVE-2021-22538HIGH8.8A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0...
CVE-2021-29663MEDIUM4.8CourseMS (aka Course Registration Management System) 2.1 is affected by cross-site scripting (XSS). When an attacker wit...
CVE-2021-26943HIGH8.2The UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary...
CVE-2021-29662HIGH7.5The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginni...
CVE-2021-23007MEDIUM5.3On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclose...
CVE-2021-23006MEDIUM6.1On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerabili...
CVE-2021-23005CRITICAL9.1On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic...
CVE-2021-23004HIGH7.5On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x ...
CVE-2021-23003HIGH7.5On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x ...
CVE-2021-23002MEDIUM4.5When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or a...
CVE-2021-23001MEDIUM4.3On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before ...
CVE-2021-23000HIGH7.5On BIG-IP versions 13.1.3.4-13.1.3.6 and 12.1.5.2, if the tmm.http.rfc.enforcement BigDB key is enabled in a BIG-IP syst...
CVE-2021-22999HIGH7.5On versions 15.0.x before 15.1.0 and 14.1.x before 14.1.4, the BIG-IP system provides an option to connect HTTP/2 client...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now