2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38022 | MEDIUM | 6.5 | 0.9% | Dec 23, 2021 | Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to le... |
| CVE-2021-38021 | MEDIUM | 6.5 | 0.8% | Dec 23, 2021 | Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navi... |
| CVE-2021-38020 | MEDIUM | 4.3 | 0.7% | Dec 23, 2021 | Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote at... |
| CVE-2021-38019 | MEDIUM | 6.5 | 0.8% | Dec 23, 2021 | Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-o... |
| CVE-2021-38018 | MEDIUM | 6.5 | 0.8% | Dec 23, 2021 | Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform d... |
| CVE-2021-38010 | MEDIUM | 6.5 | 0.9% | Dec 23, 2021 | Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had... |
| CVE-2021-38009 | MEDIUM | 6.5 | 0.8% | Dec 23, 2021 | Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-ori... |
| CVE-2021-43853 | MEDIUM | 5.4 | 0.8% | Dec 22, 2021 | Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package ... |
| CVE-2021-44544 | MEDIUM | 6.1 | 9.5% | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is... |
| CVE-2021-44471 | MEDIUM | 6.1 | 0.7% | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb... |
| CVE-2021-36885 | MEDIUM | 6.1 | 0.8% | Dec 22, 2021 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 Word... |
| CVE-2021-31558 | MEDIUM | 6.1 | 10.6% | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb... |
| CVE-2021-23228 | MEDIUM | 6.1 | 0.6% | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are... |
| CVE-2021-21937 | MEDIUM | 6.5 | 1.2% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21935 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21934 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21933 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21932 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21931 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_fi... |
| CVE-2021-21930 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filt... |
| CVE-2021-21929 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_fi... |
| CVE-2021-21928 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_fil... |
| CVE-2021-21927 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21926 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21925 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now