2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36189MEDIUM4.9A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allow...
CVE-2021-43811HIGH7.8Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses Y...
CVE-2021-4048CRITICAL9.1An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10....
CVE-2021-44529CRITICAL9.8A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut...
CVE-2021-43546MEDIUM4.3It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerabili...
CVE-2021-43545MEDIUM6.5Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thun...
CVE-2021-43544MEDIUM6.1When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the addre...
CVE-2021-43543MEDIUM6.1Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additio...
CVE-2021-43542MEDIUM6.5Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading ext...
CVE-2021-43541MEDIUM6.5When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly esca...
CVE-2021-43540MEDIUM6.5WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that ...
CVE-2021-43539HIGH8.8Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within t...
CVE-2021-43538MEDIUM4.3By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that ha...
CVE-2021-43537HIGH8.8An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a po...
CVE-2021-43536MEDIUM6.5Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. Th...
CVE-2021-43535HIGH8.8A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory c...
CVE-2021-43534HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of...
CVE-2021-43533MEDIUM4.3When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting ...
CVE-2021-43532MEDIUM6.1The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that tri...
CVE-2021-43531MEDIUM4.3When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element cl...
CVE-2021-43530MEDIUM6.1A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a ...
CVE-2021-43528MEDIUM6.5Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to thi...
CVE-2021-43527CRITICAL9.8NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER...
CVE-2021-38510HIGH8.8The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run c...
CVE-2021-38509MEDIUM4.3Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled)...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now