2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-43204MEDIUM4.4A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6....
CVE-2021-36189MEDIUM4.9A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allow...
CVE-2021-43546MEDIUM4.3It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerabili...
CVE-2021-43545MEDIUM6.5Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thun...
CVE-2021-43544MEDIUM6.1When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the addre...
CVE-2021-43543MEDIUM6.1Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additio...
CVE-2021-43542MEDIUM6.5Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading ext...
CVE-2021-43541MEDIUM6.5When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly esca...
CVE-2021-43540MEDIUM6.5WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that ...
CVE-2021-43538MEDIUM4.3By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that ha...
CVE-2021-43536MEDIUM6.5Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. Th...
CVE-2021-43533MEDIUM4.3When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting ...
CVE-2021-43532MEDIUM6.1The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that tri...
CVE-2021-43531MEDIUM4.3When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element cl...
CVE-2021-43530MEDIUM6.1A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a ...
CVE-2021-43528MEDIUM6.5Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to thi...
CVE-2021-38509MEDIUM4.3Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled)...
CVE-2021-38508MEDIUM4.3By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolo...
CVE-2021-38507MEDIUM6.5The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while r...
CVE-2021-38506MEDIUM4.3Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user....
CVE-2021-38505MEDIUM6.5Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to ...
CVE-2021-23861MEDIUM6.5By executing a special command, an user with administrative rights can get access to extended debug functionality on the...
CVE-2021-23860MEDIUM6.1An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To ...
CVE-2021-36720MEDIUM6.1PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies ...
CVE-2021-36718MEDIUM6.5SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now