2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22230 | HIGH | 7.2 | 1.0% | Jul 7, 2021 | Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability a... |
| CVE-2021-20780 | HIGH | 8.8 | 0.9% | Jul 7, 2021 | Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote at... |
| CVE-2021-20779 | HIGH | 8.8 | 0.9% | Jul 7, 2021 | Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.... |
| CVE-2021-20739 | HIGH | 8.8 | 0.5% | Jul 7, 2021 | WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, a... |
| CVE-2021-35039 | HIGH | 7.8 | 0.2% | Jul 7, 2021 | kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONF... |
| CVE-2021-22229 | HIGH | 7.5 | 1.1% | Jul 6, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was... |
| CVE-2021-32740 | HIGH | 7.5 | 2.2% | Jul 6, 2021 | Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncon... |
| CVE-2021-24451 | HIGH | 7.2 | 1.4% | Jul 6, 2021 | The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in... |
| CVE-2021-24005 | HIGH | 7.5 | 0.6% | Jul 6, 2021 | Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions befo... |
| CVE-2021-35331 | HIGH | 7.8 | 1.6% | Jul 5, 2021 | In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple... |
| CVE-2021-36148 | HIGH | 7.8 | 0.7% | Jul 2, 2021 | An issue was discovered in ACRN before 2.5. dmar_free_irte in hypervisor/arch/x86/vtd.c allows an irte_alloc_bitmap buff... |
| CVE-2021-36147 | HIGH | 7.5 | 1.0% | Jul 2, 2021 | An issue was discovered in ACRN before 2.5. It allows a devicemodel/hw/pci/virtio/virtio_net.c virtio_net_ping_rxq NULL ... |
| CVE-2021-36146 | HIGH | 7.5 | 1.2% | Jul 2, 2021 | ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer. |
| CVE-2021-36145 | HIGH | 7.5 | 1.0% | Jul 2, 2021 | The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry. |
| CVE-2021-36144 | HIGH | 7.5 | 1.0% | Jul 2, 2021 | The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/p... |
| CVE-2021-36143 | HIGH | 7.5 | 1.2% | Jul 2, 2021 | ACRN before 2.5 has a hw/pci/virtio/virtio.c vq_endchains NULL Pointer Dereference. |
| CVE-2021-34527 | HIGH | 8.8 | 99.8% | Jul 2, 2021 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file ... |
| CVE-2021-30557 | HIGH | 8.8 | 11.7% | Jul 2, 2021 | Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install ... |
| CVE-2021-30556 | HIGH | 8.8 | 1.7% | Jul 2, 2021 | Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap... |
| CVE-2021-30555 | HIGH | 8.8 | 1.4% | Jul 2, 2021 | Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a ... |
| CVE-2021-30554 | HIGH | 8.8 | 7.4% | Jul 2, 2021 | Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-27950 | HIGH | 8.8 | 1.7% | Jul 2, 2021 | A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to exec... |
| CVE-2021-3613 | HIGH | 7.8 | 0.5% | Jul 2, 2021 | OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL confi... |
| CVE-2021-3606 | HIGH | 7.8 | 0.3% | Jul 2, 2021 | OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL c... |
| CVE-2021-36132 | HIGH | 8.8 | 1.0% | Jul 2, 2021 | An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now