2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-38022MEDIUM6.5Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to le...
CVE-2021-38021MEDIUM6.5Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navi...
CVE-2021-38020MEDIUM4.3Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote at...
CVE-2021-38019MEDIUM6.5Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-o...
CVE-2021-38018MEDIUM6.5Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform d...
CVE-2021-38010MEDIUM6.5Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had...
CVE-2021-38009MEDIUM6.5Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-ori...
CVE-2021-43853MEDIUM5.4Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package ...
CVE-2021-44544MEDIUM6.1DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is...
CVE-2021-44471MEDIUM6.1DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb...
CVE-2021-36885MEDIUM6.1Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 Word...
CVE-2021-31558MEDIUM6.1DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb...
CVE-2021-23228MEDIUM6.1DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are...
CVE-2021-21937MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21935MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21934MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21933MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21932MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21931MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_fi...
CVE-2021-21930MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filt...
CVE-2021-21929MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_fi...
CVE-2021-21928MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_fil...
CVE-2021-21927MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21926MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21925MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now