2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-30530HIGH8.8Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out ...
CVE-2021-30529HIGH8.8Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a...
CVE-2021-30528HIGH8.8Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had ...
CVE-2021-30527HIGH8.8Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a mal...
CVE-2021-30526HIGH8.8Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to insta...
CVE-2021-30525HIGH8.8Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a...
CVE-2021-30524HIGH8.8Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a ...
CVE-2021-30523HIGH8.8Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap co...
CVE-2021-30522HIGH8.8Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap ...
CVE-2021-30521HIGH8.8Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform ...
CVE-2021-20517HIGH8.8IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse ...
CVE-2021-22222HIGH7.5Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafte...
CVE-2021-24340HIGH7.5The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimit...
CVE-2021-24337HIGH8.8The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is no...
CVE-2021-24336HIGH7.2The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using ...
CVE-2021-33898HIGH8.1In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php ...
CVE-2021-33879HIGH8.1Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM p...
CVE-2021-31701HIGH7.5Mintty before 3.4.7 mishandles Bracketed Paste Mode.
CVE-2021-29500HIGH7.5bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BU...
CVE-2021-30520HIGH8.8Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install ...
CVE-2021-30519HIGH8.8Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a...
CVE-2021-30518HIGH8.8Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exp...
CVE-2021-30517HIGH8.8Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corru...
CVE-2021-30516HIGH8.8Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised th...
CVE-2021-30515HIGH8.8Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now