2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20846 | HIGH | 8.8 | 0.7% | Nov 24, 2021 | Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allow... |
| CVE-2021-20845 | HIGH | 8.8 | 0.5% | Nov 24, 2021 | Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote at... |
| CVE-2021-20835 | HIGH | 7.5 | 1.3% | Nov 24, 2021 | Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and... |
| CVE-2021-28709 | HIGH | 7.8 | 0.3% | Nov 24, 2021 | issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text expl... |
| CVE-2021-28705 | HIGH | 7.8 | 0.3% | Nov 24, 2021 | issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text expl... |
| CVE-2021-42306 | HIGH | 8.1 | 3.1% | Nov 24, 2021 | An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as ... |
| CVE-2021-28708 | HIGH | 8.8 | 0.3% | Nov 24, 2021 | PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects... |
| CVE-2021-28707 | HIGH | 8.8 | 0.3% | Nov 24, 2021 | PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects... |
| CVE-2021-28706 | HIGH | 8.6 | 2.1% | Nov 24, 2021 | guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be ab... |
| CVE-2021-28704 | HIGH | 8.8 | 0.3% | Nov 24, 2021 | PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects... |
| CVE-2021-38003 | HIGH | 8.8 | 36.2% | Nov 23, 2021 | Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo... |
| CVE-2021-38001 | HIGH | 8.8 | 26.7% | Nov 23, 2021 | Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corrup... |
| CVE-2021-37998 | HIGH | 8.8 | 0.9% | Nov 23, 2021 | Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exp... |
| CVE-2021-37997 | HIGH | 8.8 | 0.9% | Nov 23, 2021 | Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign ... |
| CVE-2021-35033 | HIGH | 7.8 | 0.4% | Nov 23, 2021 | A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configu... |
| CVE-2021-43775 | HIGH | 8.6 | 1.8% | Nov 23, 2021 | Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnera... |
| CVE-2021-41281 | HIGH | 7.5 | 1.5% | Nov 23, 2021 | Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with... |
| CVE-2021-38891 | HIGH | 7.5 | 0.7% | Nov 23, 2021 | IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow... |
| CVE-2021-38890 | HIGH | 7.5 | 1.5% | Nov 23, 2021 | IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remot... |
| CVE-2021-36335 | HIGH | 8.8 | 1.1% | Nov 23, 2021 | Dell EMC CloudLink 7.1 and all prior versions contain an Improper Input Validation Vulnerability. A remote low privilege... |
| CVE-2021-36313 | HIGH | 7.2 | 2.1% | Nov 23, 2021 | Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged at... |
| CVE-2021-36311 | HIGH | 7.8 | 0.2% | Nov 23, 2021 | Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with... |
| CVE-2021-36301 | HIGH | 7.2 | 27.7% | Nov 23, 2021 | Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Raca... |
| CVE-2021-36300 | HIGH | 8.2 | 33.3% | Nov 23, 2021 | iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attack... |
| CVE-2021-36299 | HIGH | 8.1 | 29.6% | Nov 23, 2021 | Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now