2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43204 | MEDIUM | 4.4 | 0.3% | Dec 9, 2021 | A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.... |
| CVE-2021-36189 | MEDIUM | 4.9 | 0.4% | Dec 9, 2021 | A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allow... |
| CVE-2021-43546 | MEDIUM | 4.3 | 1.4% | Dec 8, 2021 | It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerabili... |
| CVE-2021-43545 | MEDIUM | 6.5 | 1.6% | Dec 8, 2021 | Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thun... |
| CVE-2021-43544 | MEDIUM | 6.1 | 0.5% | Dec 8, 2021 | When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the addre... |
| CVE-2021-43543 | MEDIUM | 6.1 | 1.4% | Dec 8, 2021 | Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additio... |
| CVE-2021-43542 | MEDIUM | 6.5 | 1.7% | Dec 8, 2021 | Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading ext... |
| CVE-2021-43541 | MEDIUM | 6.5 | 1.6% | Dec 8, 2021 | When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly esca... |
| CVE-2021-43540 | MEDIUM | 6.5 | 0.9% | Dec 8, 2021 | WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that ... |
| CVE-2021-43538 | MEDIUM | 4.3 | 1.2% | Dec 8, 2021 | By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that ha... |
| CVE-2021-43536 | MEDIUM | 6.5 | 1.7% | Dec 8, 2021 | Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. Th... |
| CVE-2021-43533 | MEDIUM | 4.3 | 0.5% | Dec 8, 2021 | When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting ... |
| CVE-2021-43532 | MEDIUM | 6.1 | 0.5% | Dec 8, 2021 | The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that tri... |
| CVE-2021-43531 | MEDIUM | 4.3 | 0.3% | Dec 8, 2021 | When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element cl... |
| CVE-2021-43530 | MEDIUM | 6.1 | 1.4% | Dec 8, 2021 | A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a ... |
| CVE-2021-43528 | MEDIUM | 6.5 | 1.3% | Dec 8, 2021 | Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to thi... |
| CVE-2021-38509 | MEDIUM | 4.3 | 1.6% | Dec 8, 2021 | Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled)... |
| CVE-2021-38508 | MEDIUM | 4.3 | 1.5% | Dec 8, 2021 | By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolo... |
| CVE-2021-38507 | MEDIUM | 6.5 | 0.8% | Dec 8, 2021 | The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while r... |
| CVE-2021-38506 | MEDIUM | 4.3 | 1.5% | Dec 8, 2021 | Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user.... |
| CVE-2021-38505 | MEDIUM | 6.5 | 1.1% | Dec 8, 2021 | Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to ... |
| CVE-2021-23861 | MEDIUM | 6.5 | 0.8% | Dec 8, 2021 | By executing a special command, an user with administrative rights can get access to extended debug functionality on the... |
| CVE-2021-23860 | MEDIUM | 6.1 | 0.5% | Dec 8, 2021 | An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To ... |
| CVE-2021-36720 | MEDIUM | 6.1 | 0.6% | Dec 8, 2021 | PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies ... |
| CVE-2021-36718 | MEDIUM | 6.5 | 0.5% | Dec 8, 2021 | SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now