2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38508 | MEDIUM | 4.3 | 1.5% | Dec 8, 2021 | By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolo... |
| CVE-2021-38507 | MEDIUM | 6.5 | 0.8% | Dec 8, 2021 | The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while r... |
| CVE-2021-38506 | MEDIUM | 4.3 | 1.5% | Dec 8, 2021 | Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user.... |
| CVE-2021-38505 | MEDIUM | 6.5 | 1.1% | Dec 8, 2021 | Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to ... |
| CVE-2021-38504 | HIGH | 8.8 | 1.6% | Dec 8, 2021 | When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have r... |
| CVE-2021-38503 | CRITICAL | 10 | 3.8% | Dec 8, 2021 | The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such ... |
| CVE-2021-37941 | HIGH | 7.8 | 0.2% | Dec 8, 2021 | A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a maliciou... |
| CVE-2021-23862 | HIGH | 7.2 | 1.4% | Dec 8, 2021 | A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in... |
| CVE-2021-23861 | MEDIUM | 6.5 | 0.8% | Dec 8, 2021 | By executing a special command, an user with administrative rights can get access to extended debug functionality on the... |
| CVE-2021-23860 | MEDIUM | 6.1 | 0.5% | Dec 8, 2021 | An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To ... |
| CVE-2021-23859 | HIGH | 7.5 | 1.0% | Dec 8, 2021 | An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standal... |
| CVE-2021-21957 | HIGH | 7.3 | 1.2% | Dec 8, 2021 | A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2... |
| CVE-2021-21951 | CRITICAL | 10 | 2.4% | Dec 8, 2021 | An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security... |
| CVE-2021-21950 | CRITICAL | 10 | 2.4% | Dec 8, 2021 | An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security... |
| CVE-2021-36720 | MEDIUM | 6.1 | 0.6% | Dec 8, 2021 | PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies ... |
| CVE-2021-36719 | HIGH | 8.8 | 1.1% | Dec 8, 2021 | PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulner... |
| CVE-2021-36718 | MEDIUM | 6.5 | 0.5% | Dec 8, 2021 | SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report... |
| CVE-2021-43978 | HIGH | 8.1 | 0.7% | Dec 8, 2021 | Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users... |
| CVE-2021-43809 | HIGH | 7.3 | 2.8% | Dec 8, 2021 | `Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working ... |
| CVE-2021-43399 | HIGH | 7.5 | 1.4% | Dec 8, 2021 | The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the lengt... |
| CVE-2021-41025 | CRITICAL | 9.8 | 1.4% | Dec 8, 2021 | Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.1... |
| CVE-2021-41017 | HIGH | 8.8 | 1.9% | Dec 8, 2021 | Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 thro... |
| CVE-2021-36195 | HIGH | 8.8 | 1.1% | Dec 8, 2021 | Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 thro... |
| CVE-2021-36173 | HIGH | 8.8 | 1.4% | Dec 8, 2021 | A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 thr... |
| CVE-2021-41030 | CRITICAL | 9.1 | 1.0% | Dec 8, 2021 | An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now