2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38508MEDIUM4.3By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolo...
CVE-2021-38507MEDIUM6.5The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while r...
CVE-2021-38506MEDIUM4.3Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user....
CVE-2021-38505MEDIUM6.5Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to ...
CVE-2021-38504HIGH8.8When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have r...
CVE-2021-38503CRITICAL10The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such ...
CVE-2021-37941HIGH7.8A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a maliciou...
CVE-2021-23862HIGH7.2A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in...
CVE-2021-23861MEDIUM6.5By executing a special command, an user with administrative rights can get access to extended debug functionality on the...
CVE-2021-23860MEDIUM6.1An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To ...
CVE-2021-23859HIGH7.5An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standal...
CVE-2021-21957HIGH7.3A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2...
CVE-2021-21951CRITICAL10An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security...
CVE-2021-21950CRITICAL10An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security...
CVE-2021-36720MEDIUM6.1PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies ...
CVE-2021-36719HIGH8.8PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulner...
CVE-2021-36718MEDIUM6.5SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report...
CVE-2021-43978HIGH8.1Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users...
CVE-2021-43809HIGH7.3`Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working ...
CVE-2021-43399HIGH7.5The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the lengt...
CVE-2021-41025CRITICAL9.8Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.1...
CVE-2021-41017HIGH8.8Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 thro...
CVE-2021-36195HIGH8.8Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 thro...
CVE-2021-36173HIGH8.8A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 thr...
CVE-2021-41030CRITICAL9.1An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now