2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38007 | HIGH | 8.8 | 0.9% | Dec 23, 2021 | Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corrup... |
| CVE-2021-38006 | HIGH | 8.8 | 1.0% | Dec 23, 2021 | Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exp... |
| CVE-2021-38005 | HIGH | 8.8 | 1.0% | Dec 23, 2021 | Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-43853 | MEDIUM | 5.4 | 0.8% | Dec 22, 2021 | Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package ... |
| CVE-2021-45461 | CRITICAL | 9.8 | 21.7% | Dec 22, 2021 | FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remo... |
| CVE-2021-44544 | MEDIUM | 6.1 | 9.5% | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is... |
| CVE-2021-44471 | MEDIUM | 6.1 | 0.7% | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb... |
| CVE-2021-40418 | CRITICAL | 9.8 | 17.9% | Dec 22, 2021 | When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assig... |
| CVE-2021-40417 | CRITICAL | 9.8 | 15.7% | Dec 22, 2021 | When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decodin... |
| CVE-2021-40394 | CRITICAL | 9.8 | 2.9% | Dec 22, 2021 | An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.... |
| CVE-2021-40393 | CRITICAL | 9.8 | 3.1% | Dec 22, 2021 | An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.... |
| CVE-2021-39306 | CRITICAL | 9.8 | 1.3% | Dec 22, 2021 | A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an a... |
| CVE-2021-36886 | HIGH | 8.8 | 0.5% | Dec 22, 2021 | Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (ve... |
| CVE-2021-36885 | MEDIUM | 6.1 | 0.8% | Dec 22, 2021 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 Word... |
| CVE-2021-31558 | MEDIUM | 6.1 | 10.6% | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arb... |
| CVE-2021-23228 | MEDIUM | 6.1 | 0.6% | Dec 22, 2021 | DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are... |
| CVE-2021-21953 | HIGH | 8.1 | 1.0% | Dec 22, 2021 | An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Ho... |
| CVE-2021-21952 | CRITICAL | 9.8 | 1.3% | Dec 22, 2021 | An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security b... |
| CVE-2021-21937 | MEDIUM | 6.5 | 1.2% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21936 | HIGH | 8.8 | 1.4% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21935 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21934 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21933 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21932 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ... |
| CVE-2021-21931 | MEDIUM | 6.5 | 1.1% | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_fi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now