2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32576 | HIGH | 7.8 | 0.2% | Aug 5, 2021 | Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handl... |
| CVE-2021-29978 | CRITICAL | 9.8 | 2.8% | Aug 5, 2021 | Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd pa... |
| CVE-2021-29977 | HIGH | 8.8 | 1.0% | Aug 5, 2021 | Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corru... |
| CVE-2021-29976 | HIGH | 8.8 | 1.2% | Aug 5, 2021 | Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bug... |
| CVE-2021-29975 | MEDIUM | 6.5 | 1.0% | Aug 5, 2021 | Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or format... |
| CVE-2021-29974 | MEDIUM | 4.3 | 0.8% | Aug 5, 2021 | When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would... |
| CVE-2021-29973 | HIGH | 8.8 | 0.8% | Aug 5, 2021 | Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected t... |
| CVE-2021-29972 | HIGH | 8.8 | 1.0% | Aug 5, 2021 | A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library r... |
| CVE-2021-29971 | CRITICAL | 9.8 | 1.0% | Aug 5, 2021 | If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespectiv... |
| CVE-2021-29970 | HIGH | 8.8 | 1.4% | Aug 5, 2021 | A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This... |
| CVE-2021-29969 | MEDIUM | 5.9 | 1.2% | Aug 5, 2021 | If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses pri... |
| CVE-2021-25448 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in w... |
| CVE-2021-25447 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause l... |
| CVE-2021-25446 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause a... |
| CVE-2021-25445 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access int... |
| CVE-2021-25444 | MEDIUM | 5.5 | 0.8% | Aug 5, 2021 | An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileg... |
| CVE-2021-25443 | MEDIUM | 5.3 | 0.1% | Aug 5, 2021 | A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attac... |
| CVE-2021-23849 | HIGH | 8.8 | 0.5% | Aug 5, 2021 | A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected s... |
| CVE-2021-22241 | MEDIUM | 5.4 | 1.0% | Aug 5, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a sto... |
| CVE-2021-22240 | MEDIUM | 4.3 | 0.7% | Aug 5, 2021 | Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on... |
| CVE-2021-21863 | HIGH | 7.8 | 1.2% | Aug 5, 2021 | A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH COD... |
| CVE-2021-21739 | MEDIUM | 4.6 | 0.2% | Aug 5, 2021 | A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficie... |
| CVE-2021-21738 | MEDIUM | 6.1 | 0.6% | Aug 5, 2021 | ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient inp... |
| CVE-2021-37625 | HIGH | 7.5 | 0.9% | Aug 5, 2021 | Skytable is an open source NoSQL database. In versions prior to 0.6.4 an incorrect check of return value of the accept f... |
| CVE-2021-38138 | MEDIUM | 5.4 | 1.5% | Aug 5, 2021 | OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now