2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20672 | MEDIUM | 6.1 | 0.9% | Mar 10, 2021 | Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Ser... |
| CVE-2021-20669 | MEDIUM | 4.7 | 0.8% | Mar 10, 2021 | Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read a... |
| CVE-2021-20667 | MEDIUM | 5.4 | 0.7% | Mar 10, 2021 | Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI version... |
| CVE-2021-28116 | MEDIUM | 5.3 | 13.0% | Mar 9, 2021 | Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bou... |
| CVE-2021-28115 | MEDIUM | 6.1 | 0.9% | Mar 9, 2021 | The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation. |
| CVE-2021-23273 | MEDIUM | 5.4 | 0.6% | Mar 9, 2021 | The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS... |
| CVE-2021-3411 | MEDIUM | 6.7 | 0.4% | Mar 9, 2021 | A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a... |
| CVE-2021-20255 | MEDIUM | 5.5 | 0.4% | Mar 9, 2021 | A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This ... |
| CVE-2021-21295 | MEDIUM | 5.9 | 18.9% | Mar 9, 2021 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h... |
| CVE-2021-20246 | MEDIUM | 5.5 | 1.2% | Mar 9, 2021 | A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by Im... |
| CVE-2021-20245 | MEDIUM | 5.5 | 1.2% | Mar 9, 2021 | A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagic... |
| CVE-2021-20244 | MEDIUM | 5.5 | 1.2% | Mar 9, 2021 | A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed... |
| CVE-2021-21369 | MEDIUM | 6.5 | 1.5% | Mar 9, 2021 | Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 th... |
| CVE-2021-21189 | MEDIUM | 4.3 | 1.5% | Mar 9, 2021 | Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass n... |
| CVE-2021-21187 | MEDIUM | 4.3 | 1.5% | Mar 9, 2021 | Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perfo... |
| CVE-2021-21186 | MEDIUM | 4.3 | 1.1% | Mar 9, 2021 | Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who con... |
| CVE-2021-21185 | MEDIUM | 4.3 | 1.3% | Mar 9, 2021 | Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a... |
| CVE-2021-21184 | MEDIUM | 4.3 | 1.1% | Mar 9, 2021 | Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to lea... |
| CVE-2021-21183 | MEDIUM | 4.3 | 1.0% | Mar 9, 2021 | Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to lea... |
| CVE-2021-21182 | MEDIUM | 6.5 | 1.9% | Mar 9, 2021 | Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had ... |
| CVE-2021-21181 | MEDIUM | 6.5 | 1.6% | Mar 9, 2021 | Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain ... |
| CVE-2021-21178 | MEDIUM | 6.5 | 1.6% | Mar 9, 2021 | Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote... |
| CVE-2021-21177 | MEDIUM | 6.5 | 17.3% | Mar 9, 2021 | Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain p... |
| CVE-2021-21176 | MEDIUM | 6.5 | 1.7% | Mar 9, 2021 | Inappropriate implementation in full screen mode in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to spo... |
| CVE-2021-21175 | MEDIUM | 6.5 | 1.2% | Mar 9, 2021 | Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now