2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32576HIGH7.8Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handl...
CVE-2021-29978CRITICAL9.8Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd pa...
CVE-2021-29977HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corru...
CVE-2021-29976HIGH8.8Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bug...
CVE-2021-29975MEDIUM6.5Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or format...
CVE-2021-29974MEDIUM4.3When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would...
CVE-2021-29973HIGH8.8Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected t...
CVE-2021-29972HIGH8.8A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library r...
CVE-2021-29971CRITICAL9.8If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespectiv...
CVE-2021-29970HIGH8.8A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This...
CVE-2021-29969MEDIUM5.9If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses pri...
CVE-2021-25448MEDIUM5.3Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in w...
CVE-2021-25447MEDIUM5.3Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause l...
CVE-2021-25446MEDIUM5.3Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause a...
CVE-2021-25445MEDIUM5.3Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access int...
CVE-2021-25444MEDIUM5.5An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileg...
CVE-2021-25443MEDIUM5.3A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attac...
CVE-2021-23849HIGH8.8A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected s...
CVE-2021-22241MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a sto...
CVE-2021-22240MEDIUM4.3Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on...
CVE-2021-21863HIGH7.8A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH COD...
CVE-2021-21739MEDIUM4.6A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficie...
CVE-2021-21738MEDIUM6.1ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient inp...
CVE-2021-37625HIGH7.5Skytable is an open source NoSQL database. In versions prior to 0.6.4 an incorrect check of return value of the accept f...
CVE-2021-38138MEDIUM5.4OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now