2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23977 | MEDIUM | 5.3 | 0.9% | Feb 26, 2021 | Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read... |
| CVE-2021-23963 | MEDIUM | 4.3 | 0.7% | Feb 26, 2021 | When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user in... |
| CVE-2021-23959 | MEDIUM | 6.1 | 0.6% | Feb 26, 2021 | An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the addre... |
| CVE-2021-23958 | MEDIUM | 6.5 | 0.9% | Feb 26, 2021 | The browser could have been confused into transferring a screen sharing state into another tab, which would leak uninten... |
| CVE-2021-23956 | MEDIUM | 6.5 | 1.0% | Feb 26, 2021 | An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading... |
| CVE-2021-23955 | MEDIUM | 6.1 | 0.7% | Feb 26, 2021 | The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to c... |
| CVE-2021-23953 | MEDIUM | 4.3 | 1.1% | Feb 26, 2021 | If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin informatio... |
| CVE-2021-21724 | MEDIUM | 4.4 | 0.4% | Feb 26, 2021 | A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scena... |
| CVE-2021-21330 | MEDIUM | 6.1 | 1.9% | Feb 26, 2021 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is... |
| CVE-2021-23975 | MEDIUM | 6.5 | 1.0% | Feb 26, 2021 | The developer page about:memory has a Measure function for exploring what object types the browser has allocated and the... |
| CVE-2021-23974 | MEDIUM | 6.1 | 0.8% | Feb 26, 2021 | The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to b... |
| CVE-2021-23973 | MEDIUM | 6.5 | 1.4% | Feb 26, 2021 | When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the conten... |
| CVE-2021-23971 | MEDIUM | 6.5 | 1.0% | Feb 26, 2021 | When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy... |
| CVE-2021-23970 | MEDIUM | 6.5 | 1.0% | Feb 26, 2021 | Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm... |
| CVE-2021-23969 | MEDIUM | 4.3 | 1.2% | Feb 26, 2021 | As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure tha... |
| CVE-2021-23968 | MEDIUM | 4.3 | 1.2% | Feb 26, 2021 | If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported... |
| CVE-2021-21328 | MEDIUM | 5.3 | 1.6% | Feb 26, 2021 | Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps ... |
| CVE-2021-24114 | MEDIUM | 5.7 | 2.8% | Feb 25, 2021 | Microsoft Teams iOS Information Disclosure Vulnerability |
| CVE-2021-24113 | MEDIUM | 5.4 | 1.3% | Feb 25, 2021 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2021-24109 | MEDIUM | 6.8 | 2.0% | Feb 25, 2021 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2021-24106 | MEDIUM | 5.5 | 0.9% | Feb 25, 2021 | Windows DirectX Information Disclosure Vulnerability |
| CVE-2021-24101 | MEDIUM | 6.5 | 2.8% | Feb 25, 2021 | Microsoft Dataverse Information Disclosure Vulnerability |
| CVE-2021-24100 | MEDIUM | 5 | 2.8% | Feb 25, 2021 | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2021-24099 | MEDIUM | 6.5 | 2.9% | Feb 25, 2021 | Skype for Business and Lync Denial of Service Vulnerability |
| CVE-2021-24098 | MEDIUM | 5.5 | 1.5% | Feb 25, 2021 | Windows Console Driver Denial of Service Vulnerability |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now