2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-30633CRITICAL9.6Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised th...
CVE-2021-30632HIGH8.8Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c...
CVE-2021-30630MEDIUM4.3Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromis...
CVE-2021-30629HIGH8.8Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the r...
CVE-2021-30628HIGH8.8Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit s...
CVE-2021-30627HIGH8.8Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit h...
CVE-2021-30626HIGH8.8Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exp...
CVE-2021-30625HIGH8.8Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user ...
CVE-2021-42109CRITICAL9.8VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
CVE-2021-29906MEDIUM5.5IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a...
CVE-2021-41802MEDIUM5.4HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID ...
CVE-2021-32029MEDIUM6.5A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated datab...
CVE-2021-20600MEDIUM5.9Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versi...
CVE-2021-41976MEDIUM5.3Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function t...
CVE-2021-41975CRITICAL9.1TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to del...
CVE-2021-41974CRITICAL9.1Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view a...
CVE-2021-41920HIGH7.5webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection o...
CVE-2021-41919HIGH8.8webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without...
CVE-2021-41918MEDIUM5.4webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect s...
CVE-2021-41917MEDIUM5.4webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or edit...
CVE-2021-41916HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to creat...
CVE-2021-41825MEDIUM5.3Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.
CVE-2021-41568MEDIUM6.5Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original f...
CVE-2021-41567MEDIUM6.1The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticate...
CVE-2021-41566CRITICAL9.8The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of f...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now