2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36189 | MEDIUM | 4.9 | 0.4% | Dec 9, 2021 | A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allow... |
| CVE-2021-43811 | HIGH | 7.8 | 2.4% | Dec 8, 2021 | Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses Y... |
| CVE-2021-4048 | CRITICAL | 9.1 | 2.6% | Dec 8, 2021 | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.... |
| CVE-2021-44529 | CRITICAL | 9.8 | 99.1% | Dec 8, 2021 | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut... |
| CVE-2021-43546 | MEDIUM | 4.3 | 1.4% | Dec 8, 2021 | It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerabili... |
| CVE-2021-43545 | MEDIUM | 6.5 | 1.6% | Dec 8, 2021 | Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thun... |
| CVE-2021-43544 | MEDIUM | 6.1 | 0.5% | Dec 8, 2021 | When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the addre... |
| CVE-2021-43543 | MEDIUM | 6.1 | 1.4% | Dec 8, 2021 | Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additio... |
| CVE-2021-43542 | MEDIUM | 6.5 | 1.7% | Dec 8, 2021 | Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading ext... |
| CVE-2021-43541 | MEDIUM | 6.5 | 1.6% | Dec 8, 2021 | When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly esca... |
| CVE-2021-43540 | MEDIUM | 6.5 | 0.9% | Dec 8, 2021 | WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that ... |
| CVE-2021-43539 | HIGH | 8.8 | 1.6% | Dec 8, 2021 | Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within t... |
| CVE-2021-43538 | MEDIUM | 4.3 | 1.2% | Dec 8, 2021 | By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that ha... |
| CVE-2021-43537 | HIGH | 8.8 | 2.0% | Dec 8, 2021 | An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a po... |
| CVE-2021-43536 | MEDIUM | 6.5 | 1.7% | Dec 8, 2021 | Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. Th... |
| CVE-2021-43535 | HIGH | 8.8 | 1.1% | Dec 8, 2021 | A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory c... |
| CVE-2021-43534 | HIGH | 8.8 | 1.2% | Dec 8, 2021 | Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of... |
| CVE-2021-43533 | MEDIUM | 4.3 | 0.5% | Dec 8, 2021 | When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting ... |
| CVE-2021-43532 | MEDIUM | 6.1 | 0.5% | Dec 8, 2021 | The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that tri... |
| CVE-2021-43531 | MEDIUM | 4.3 | 0.3% | Dec 8, 2021 | When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element cl... |
| CVE-2021-43530 | MEDIUM | 6.1 | 1.4% | Dec 8, 2021 | A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a ... |
| CVE-2021-43528 | MEDIUM | 6.5 | 1.3% | Dec 8, 2021 | Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to thi... |
| CVE-2021-43527 | CRITICAL | 9.8 | 17.6% | Dec 8, 2021 | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER... |
| CVE-2021-38510 | HIGH | 8.8 | 1.0% | Dec 8, 2021 | The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run c... |
| CVE-2021-38509 | MEDIUM | 4.3 | 1.6% | Dec 8, 2021 | Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled)... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now