2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31784 | HIGH | 7.8 | 0.9% | Apr 26, 2021 | An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 20... |
| CVE-2021-31783 | HIGH | 7.5 | 0.6% | Apr 26, 2021 | show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the fi... |
| CVE-2021-22669 | HIGH | 8.8 | 1.2% | Apr 26, 2021 | Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA V... |
| CVE-2021-29694 | HIGH | 7.5 | 0.7% | Apr 26, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an a... |
| CVE-2021-29672 | HIGH | 7.8 | 0.3% | Apr 26, 2021 | IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper ... |
| CVE-2021-21225 | HIGH | 8.8 | 6.6% | Apr 26, 2021 | Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploi... |
| CVE-2021-21224 | HIGH | 8.8 | 57.7% | Apr 26, 2021 | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a... |
| CVE-2021-21220 | HIGH | 8.8 | 70.4% | Apr 26, 2021 | Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po... |
| CVE-2021-21214 | HIGH | 8.8 | 1.3% | Apr 26, 2021 | Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit he... |
| CVE-2021-21213 | HIGH | 8.8 | 1.5% | Apr 26, 2021 | Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap c... |
| CVE-2021-21207 | HIGH | 8.6 | 0.9% | Apr 26, 2021 | Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a... |
| CVE-2021-21206 | HIGH | 8.8 | 9.4% | Apr 26, 2021 | Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-21205 | HIGH | 8.1 | 1.5% | Apr 26, 2021 | Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to... |
| CVE-2021-21204 | HIGH | 8.8 | 1.6% | Apr 26, 2021 | Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to potentially exploit ... |
| CVE-2021-21203 | HIGH | 8.8 | 1.8% | Apr 26, 2021 | Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2021-21202 | HIGH | 8.6 | 1.0% | Apr 26, 2021 | Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install ... |
| CVE-2021-20532 | HIGH | 7.8 | 0.2% | Apr 26, 2021 | IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full ... |
| CVE-2021-23382 | HIGH | 7.5 | 2.5% | Apr 26, 2021 | The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() ... |
| CVE-2021-3472 | HIGH | 7.8 | 1.1% | Apr 26, 2021 | A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead... |
| CVE-2021-31802 | HIGH | 8.8 | 14.2% | Apr 26, 2021 | NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without au... |
| CVE-2021-20709 | HIGH | 7.2 | 0.7% | Apr 26, 2021 | Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG... |
| CVE-2021-20708 | HIGH | 7.2 | 1.2% | Apr 26, 2021 | NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm... |
| CVE-2021-20696 | HIGH | 8.8 | 2.4% | Apr 26, 2021 | DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by ... |
| CVE-2021-20695 | HIGH | 8.8 | 1.3% | Apr 26, 2021 | Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allow... |
| CVE-2021-20694 | HIGH | 8.8 | 1.7% | Apr 26, 2021 | Improper access control vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated atta... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now