2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26967MEDIUM6.1A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(...
CVE-2021-26966MEDIUM6.5A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior...
CVE-2021-26965MEDIUM6.5A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior...
CVE-2021-26964HIGH7.1A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s):...
CVE-2021-26963HIGH7.2A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver...
CVE-2021-21725MEDIUM5.7A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to ...
CVE-2021-26962HIGH7.2A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver...
CVE-2021-26961HIGH8.8A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Plat...
CVE-2021-26960HIGH8.8A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Plat...
CVE-2021-28026HIGH7.8jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicou...
CVE-2021-27907MEDIUM5.4Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describi...
CVE-2021-20665MEDIUM6.1Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movabl...
CVE-2021-20664MEDIUM6.1Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 ...
CVE-2021-20663MEDIUM6.1Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Typ...
CVE-2021-28037CRITICAL9.8An issue was discovered in the internment crate before 0.4.2 for Rust. There is a data race that can cause memory corrup...
CVE-2021-28036HIGH7.5An issue was discovered in the quinn crate before 0.7.0 for Rust. It may have invalid memory access for certain versions...
CVE-2021-28035CRITICAL9.8An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a drop of unin...
CVE-2021-28034CRITICAL9.8An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a double free ...
CVE-2021-28033CRITICAL9.8An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a...
CVE-2021-28032CRITICAL9.8An issue was discovered in the nano_arena crate before 0.5.2 for Rust. There is an aliasing violation in split_at becaus...
CVE-2021-28031CRITICAL9.8An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free...
CVE-2021-28030HIGH7.5An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized m...
CVE-2021-28029HIGH7.5An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read th...
CVE-2021-28028CRITICAL9.8An issue was discovered in the toodee crate before 0.3.0 for Rust. Row insertion can cause a double free upon an iterato...
CVE-2021-28027CRITICAL9.8An issue was discovered in the bam crate before 0.1.3 for Rust. There is an integer underflow and out-of-bounds write du...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now