2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29948LOW2.5Signatures are written to disk before and read during verification, which might be subject to a race condition when a ma...
CVE-2021-29947HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed ev...
CVE-2021-29946HIGH8.8Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking re...
CVE-2021-29945MEDIUM6.5The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash....
CVE-2021-29944MEDIUM6.1Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy preven...
CVE-2021-27659MEDIUM6.1exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input befo...
CVE-2021-27658MEDIUM5.4exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable inp...
CVE-2021-24002HIGH8.8When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been inte...
CVE-2021-24001MEDIUM4.3A compromised content process could have performed session history manipulations it should not have been able to due to ...
CVE-2021-24000LOW3.1A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when ...
CVE-2021-23999HIGH8.8If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and gr...
CVE-2021-23998MEDIUM6.5Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS pag...
CVE-2021-23997HIGH8.8Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We p...
CVE-2021-23996MEDIUM6.5By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, res...
CVE-2021-23995HIGH8.8When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with ...
CVE-2021-23994HIGH8.8A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vul...
CVE-2021-23993MEDIUM6.5An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker c...
CVE-2021-23992MEDIUM4.3Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may crea...
CVE-2021-23991MEDIUM6.8If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key...
CVE-2021-33604LOW2.5URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 thr...
CVE-2021-31412MEDIUM5.3Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14...
CVE-2021-26585MEDIUM5.5A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local d...
CVE-2021-25923HIGH8.1In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum pass...
CVE-2021-21737HIGH7.5A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection ...
CVE-2021-25656MEDIUM5.4Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now