2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38007HIGH8.8Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corrup...
CVE-2021-38006HIGH8.8Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exp...
CVE-2021-38005HIGH8.8Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap co...
CVE-2021-43853MEDIUM5.4Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package ...
CVE-2021-45461CRITICAL9.8FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remo...
CVE-2021-44544MEDIUM6.1DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is...
CVE-2021-44471MEDIUM6.1DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb...
CVE-2021-40418CRITICAL9.8When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assig...
CVE-2021-40417CRITICAL9.8When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decodin...
CVE-2021-40394CRITICAL9.8An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7....
CVE-2021-40393CRITICAL9.8An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7....
CVE-2021-39306CRITICAL9.8A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an a...
CVE-2021-36886HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (ve...
CVE-2021-36885MEDIUM6.1Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 Word...
CVE-2021-31558MEDIUM6.1DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb...
CVE-2021-23228MEDIUM6.1DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are...
CVE-2021-21953HIGH8.1An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Ho...
CVE-2021-21952CRITICAL9.8An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security b...
CVE-2021-21937MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21936HIGH8.8A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21935MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21934MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21933MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21932MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21931MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_fi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now