2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37982HIGH8.8Use after free in Incognito in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap...
CVE-2021-37981CRITICAL9.6Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the re...
CVE-2021-37980HIGH7.4Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially ...
CVE-2021-37979HIGH8.8heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to ...
CVE-2021-37978HIGH8.8Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit he...
CVE-2021-37977HIGH8.8Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exp...
CVE-2021-37960Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-30631Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-42754MEDIUM5An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 ...
CVE-2021-41023MEDIUM5.5A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated...
CVE-2021-41022HIGH7.8A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute p...
CVE-2021-36187HIGH7.5A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows...
CVE-2021-36186CRITICAL9.8A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attac...
CVE-2021-36185HIGH8.8A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM versio...
CVE-2021-36184MEDIUM6.5A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6....
CVE-2021-36183HIGH7.8An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and belo...
CVE-2021-36176MEDIUM6.1Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a ...
CVE-2021-36174HIGH7.5A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal before 6...
CVE-2021-41238HIGH7.5Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows S...
CVE-2021-41232CRITICAL9.8Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there ...
CVE-2021-41019MEDIUM6.5An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may...
CVE-2021-36181LOW3.1A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the custo...
CVE-2021-36172HIGH8.1An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal bef...
CVE-2021-32595MEDIUM6.5Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a ...
CVE-2021-26107MEDIUM4.3An improper access control vulnerability [CWE-284] in FortiManager versions 6.4.4 and 6.4.5 may allow an authenticated a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now