2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25262MEDIUM5.4Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.
CVE-2021-25255HIGH7.5Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.
CVE-2021-25254MEDIUM5.3Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
CVE-2021-43069Rejected reason: Not used
CVE-2021-32601Rejected reason: Not used
CVE-2021-47664MEDIUM5.3Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames.
CVE-2021-47663HIGH8.1Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and there...
CVE-2021-47662HIGH7.5Due to missing authorization an unauthenticated remote attacker can cause a DoS attack by connecting via HTTPS and trigg...
CVE-2021-4455CRITICAL9.8The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi...
CVE-2021-47671LOW3.3In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory lea...
CVE-2021-47670HIGH8.8In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calli...
CVE-2021-47669HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: vxcan: vxcan_xmit: fix use after free bug Aft...
CVE-2021-47668HIGH8.8In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug Afte...
CVE-2021-27289CRITICAL9.1A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1...
CVE-2021-47667CRITICAL10An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenti...
CVE-2021-24008MEDIUM5.3An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS versi...
CVE-2021-4454MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: j1939: fix errant WARN_ON_ONCE in j1939_sessio...
CVE-2021-26105HIGH8.8A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, ver...
CVE-2021-26091HIGH7.5A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Base...
CVE-2021-25635MEDIUM5.5An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with ...
CVE-2021-44789Rejected reason: Not used
CVE-2021-44788Rejected reason: Not used
CVE-2021-44787Rejected reason: Not used
CVE-2021-44786Rejected reason: Not used
CVE-2021-44785Rejected reason: Not used

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now