2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21702HIGH7.5In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a ...
CVE-2021-27213CRITICAL9.8config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load ...
CVE-2021-26929MEDIUM6.1An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor...
CVE-2021-27212HIGH7.5In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpd...
CVE-2021-27210MEDIUM6.5TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,...
CVE-2021-27209HIGH7.1In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over clear...
CVE-2021-26753CRITICAL9.9NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php...
CVE-2021-26752HIGH8.8NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoin...
CVE-2021-26751HIGH8.8NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Mo...
CVE-2021-22984MEDIUM6.1On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x be...
CVE-2021-22978HIGH8.3On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12...
CVE-2021-22977HIGH7.5On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious serv...
CVE-2021-22504CRITICAL9.8Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x...
CVE-2021-22985HIGH7.5On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consum...
CVE-2021-22983MEDIUM5.4On BIG-IP AFM version 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.5, authenticated users acce...
CVE-2021-22982HIGH7.2On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely han...
CVE-2021-22981MEDIUM4.8On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiat...
CVE-2021-22980HIGH7.8In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted sear...
CVE-2021-22979MEDIUM6.1On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12...
CVE-2021-22976HIGH7.5On BIG-IP Advanced WAF and ASM version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x befo...
CVE-2021-22975HIGH7.5On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, and 14.1.x before 14.1.3.1, under some circumstances, ...
CVE-2021-22974HIGH7.5On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and a...
CVE-2021-22973HIGH7.5On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all ...
CVE-2021-20412HIGH7.5IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptograph...
CVE-2021-20411HIGH8.1IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now