2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21702 | HIGH | 7.5 | 3.1% | Feb 15, 2021 | In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a ... |
| CVE-2021-27213 | CRITICAL | 9.8 | 2.6% | Feb 14, 2021 | config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load ... |
| CVE-2021-26929 | MEDIUM | 6.1 | 4.9% | Feb 14, 2021 | An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor... |
| CVE-2021-27212 | HIGH | 7.5 | 64.1% | Feb 14, 2021 | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpd... |
| CVE-2021-27210 | MEDIUM | 6.5 | 0.8% | Feb 13, 2021 | TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,... |
| CVE-2021-27209 | HIGH | 7.1 | 0.2% | Feb 13, 2021 | In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over clear... |
| CVE-2021-26753 | CRITICAL | 9.9 | 1.1% | Feb 12, 2021 | NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php... |
| CVE-2021-26752 | HIGH | 8.8 | 1.5% | Feb 12, 2021 | NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoin... |
| CVE-2021-26751 | HIGH | 8.8 | 1.2% | Feb 12, 2021 | NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Mo... |
| CVE-2021-22984 | MEDIUM | 6.1 | 0.6% | Feb 12, 2021 | On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x be... |
| CVE-2021-22978 | HIGH | 8.3 | 0.8% | Feb 12, 2021 | On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12... |
| CVE-2021-22977 | HIGH | 7.5 | 1.0% | Feb 12, 2021 | On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious serv... |
| CVE-2021-22504 | CRITICAL | 9.8 | 3.3% | Feb 12, 2021 | Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x... |
| CVE-2021-22985 | HIGH | 7.5 | 1.0% | Feb 12, 2021 | On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consum... |
| CVE-2021-22983 | MEDIUM | 5.4 | 0.5% | Feb 12, 2021 | On BIG-IP AFM version 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.5, authenticated users acce... |
| CVE-2021-22982 | HIGH | 7.2 | 1.0% | Feb 12, 2021 | On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely han... |
| CVE-2021-22981 | MEDIUM | 4.8 | 0.5% | Feb 12, 2021 | On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiat... |
| CVE-2021-22980 | HIGH | 7.8 | 0.3% | Feb 12, 2021 | In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted sear... |
| CVE-2021-22979 | MEDIUM | 6.1 | 0.6% | Feb 12, 2021 | On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12... |
| CVE-2021-22976 | HIGH | 7.5 | 1.0% | Feb 12, 2021 | On BIG-IP Advanced WAF and ASM version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x befo... |
| CVE-2021-22975 | HIGH | 7.5 | 0.9% | Feb 12, 2021 | On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, and 14.1.x before 14.1.3.1, under some circumstances, ... |
| CVE-2021-22974 | HIGH | 7.5 | 0.8% | Feb 12, 2021 | On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and a... |
| CVE-2021-22973 | HIGH | 7.5 | 1.0% | Feb 12, 2021 | On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all ... |
| CVE-2021-20412 | HIGH | 7.5 | 0.9% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptograph... |
| CVE-2021-20411 | HIGH | 8.1 | 0.4% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now