2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30611 | HIGH | 8.8 | 2.6% | Sep 3, 2021 | Chromium: CVE-2021-30611 Use after free in WebRTC |
| CVE-2021-30610 | HIGH | 8.8 | 3.9% | Sep 3, 2021 | Chromium: CVE-2021-30610 Use after free in Extensions API |
| CVE-2021-30609 | HIGH | 8.8 | 3.9% | Sep 3, 2021 | Chromium: CVE-2021-30609 Use after free in Sign-In |
| CVE-2021-30608 | HIGH | 8.8 | 3.9% | Sep 3, 2021 | Chromium: CVE-2021-30608 Use after free in Web Share |
| CVE-2021-30607 | HIGH | 8.8 | 3.9% | Sep 3, 2021 | Chromium: CVE-2021-30607 Use after free in Permissions |
| CVE-2021-30606 | HIGH | 8.8 | 3.9% | Sep 3, 2021 | Chromium: CVE-2021-30606 Use after free in Blink |
| CVE-2021-39193 | MEDIUM | 5.3 | 1.2% | Sep 3, 2021 | Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a... |
| CVE-2021-40492 | MEDIUM | 6.1 | 2.3% | Sep 3, 2021 | A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary... |
| CVE-2021-23437 | HIGH | 7.5 | 2.9% | Sep 3, 2021 | The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb ... |
| CVE-2021-39192 | HIGH | 7.2 | 1.0% | Sep 3, 2021 | Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.... |
| CVE-2021-39191 | MEDIUM | 6.1 | 1.6% | Sep 3, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-40494 | CRITICAL | 9.8 | 1.6% | Sep 3, 2021 | A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to ... |
| CVE-2021-40491 | MEDIUM | 6.5 | 0.9% | Sep 3, 2021 | The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they... |
| CVE-2021-40490 | HIGH | 7 | 0.3% | Sep 3, 2021 | A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux ker... |
| CVE-2021-38642 | MEDIUM | 6.1 | 1.1% | Sep 2, 2021 | Microsoft Edge for iOS Spoofing Vulnerability |
| CVE-2021-38641 | MEDIUM | 6.1 | 1.1% | Sep 2, 2021 | Microsoft Edge for Android Spoofing Vulnerability |
| CVE-2021-36930 | MEDIUM | 5.3 | 0.9% | Sep 2, 2021 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2021-26439 | MEDIUM | 4.6 | 2.5% | Sep 2, 2021 | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2021-26436 | MEDIUM | 6.1 | 2.3% | Sep 2, 2021 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2021-34436 | CRITICAL | 9.8 | 2.2% | Sep 2, 2021 | In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) v... |
| CVE-2021-39322 | MEDIUM | 6.1 | 2.2% | Sep 2, 2021 | The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file.... |
| CVE-2021-38314 | MEDIUM | 5.3 | 27.6% | Sep 2, 2021 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions availabl... |
| CVE-2021-38312 | MEDIUM | 6.5 | 1.3% | Sep 2, 2021 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in... |
| CVE-2021-36019 | LOW | 3.3 | 1.7% | Sep 2, 2021 | Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a speci... |
| CVE-2021-36018 | LOW | 3.3 | 1.7% | Sep 2, 2021 | Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a speci... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now