2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23401 | MEDIUM | 6.1 | 1.1% | Jul 5, 2021 | This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL val... |
| CVE-2021-33192 | MEDIUM | 6.1 | 2.9% | Jul 5, 2021 | A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain pa... |
| CVE-2021-36148 | HIGH | 7.8 | 0.7% | Jul 2, 2021 | An issue was discovered in ACRN before 2.5. dmar_free_irte in hypervisor/arch/x86/vtd.c allows an irte_alloc_bitmap buff... |
| CVE-2021-36147 | HIGH | 7.5 | 1.0% | Jul 2, 2021 | An issue was discovered in ACRN before 2.5. It allows a devicemodel/hw/pci/virtio/virtio_net.c virtio_net_ping_rxq NULL ... |
| CVE-2021-36146 | HIGH | 7.5 | 1.2% | Jul 2, 2021 | ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer. |
| CVE-2021-36145 | HIGH | 7.5 | 1.0% | Jul 2, 2021 | The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry. |
| CVE-2021-36144 | HIGH | 7.5 | 1.0% | Jul 2, 2021 | The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/p... |
| CVE-2021-36143 | HIGH | 7.5 | 1.2% | Jul 2, 2021 | ACRN before 2.5 has a hw/pci/virtio/virtio.c vq_endchains NULL Pointer Dereference. |
| CVE-2021-34527 | HIGH | 8.8 | 99.8% | Jul 2, 2021 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file ... |
| CVE-2021-35209 | CRITICAL | 9.8 | 3.0% | Jul 2, 2021 | An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch... |
| CVE-2021-35208 | MEDIUM | 5.4 | 1.3% | Jul 2, 2021 | An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before ... |
| CVE-2021-35207 | MEDIUM | 6.1 | 3.3% | Jul 2, 2021 | An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS v... |
| CVE-2021-34807 | MEDIUM | 6.1 | 1.0% | Jul 2, 2021 | An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the ... |
| CVE-2021-33889 | MEDIUM | 6.8 | 0.3% | Jul 2, 2021 | OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data... |
| CVE-2021-32738 | MEDIUM | 6.5 | 0.5% | Jul 2, 2021 | js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` func... |
| CVE-2021-30557 | HIGH | 8.8 | 11.7% | Jul 2, 2021 | Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install ... |
| CVE-2021-30556 | HIGH | 8.8 | 1.7% | Jul 2, 2021 | Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap... |
| CVE-2021-30555 | HIGH | 8.8 | 1.4% | Jul 2, 2021 | Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a ... |
| CVE-2021-30554 | HIGH | 8.8 | 7.4% | Jul 2, 2021 | Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-32737 | MEDIUM | 4.8 | 0.7% | Jul 2, 2021 | Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41... |
| CVE-2021-31874 | MEDIUM | 5.9 | 4.3% | Jul 2, 2021 | Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information a... |
| CVE-2021-23403 | CRITICAL | 9.8 | 1.3% | Jul 2, 2021 | All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validati... |
| CVE-2021-32639 | CRITICAL | 9.9 | 1.4% | Jul 2, 2021 | Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forger... |
| CVE-2021-23402 | CRITICAL | 9.8 | 1.2% | Jul 2, 2021 | All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality. |
| CVE-2021-32735 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now