2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29948 | LOW | 2.5 | 0.3% | Jun 24, 2021 | Signatures are written to disk before and read during verification, which might be subject to a race condition when a ma... |
| CVE-2021-29947 | HIGH | 8.8 | 0.9% | Jun 24, 2021 | Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed ev... |
| CVE-2021-29946 | HIGH | 8.8 | 1.2% | Jun 24, 2021 | Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking re... |
| CVE-2021-29945 | MEDIUM | 6.5 | 1.2% | Jun 24, 2021 | The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash.... |
| CVE-2021-29944 | MEDIUM | 6.1 | 0.7% | Jun 24, 2021 | Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy preven... |
| CVE-2021-27659 | MEDIUM | 6.1 | 1.2% | Jun 24, 2021 | exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input befo... |
| CVE-2021-27658 | MEDIUM | 5.4 | 0.9% | Jun 24, 2021 | exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable inp... |
| CVE-2021-24002 | HIGH | 8.8 | 1.2% | Jun 24, 2021 | When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been inte... |
| CVE-2021-24001 | MEDIUM | 4.3 | 0.6% | Jun 24, 2021 | A compromised content process could have performed session history manipulations it should not have been able to due to ... |
| CVE-2021-24000 | LOW | 3.1 | 0.6% | Jun 24, 2021 | A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when ... |
| CVE-2021-23999 | HIGH | 8.8 | 1.3% | Jun 24, 2021 | If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and gr... |
| CVE-2021-23998 | MEDIUM | 6.5 | 0.6% | Jun 24, 2021 | Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS pag... |
| CVE-2021-23997 | HIGH | 8.8 | 0.8% | Jun 24, 2021 | Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We p... |
| CVE-2021-23996 | MEDIUM | 6.5 | 0.7% | Jun 24, 2021 | By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, res... |
| CVE-2021-23995 | HIGH | 8.8 | 1.2% | Jun 24, 2021 | When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with ... |
| CVE-2021-23994 | HIGH | 8.8 | 1.8% | Jun 24, 2021 | A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vul... |
| CVE-2021-23993 | MEDIUM | 6.5 | 0.4% | Jun 24, 2021 | An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker c... |
| CVE-2021-23992 | MEDIUM | 4.3 | 0.5% | Jun 24, 2021 | Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may crea... |
| CVE-2021-23991 | MEDIUM | 6.8 | 1.0% | Jun 24, 2021 | If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key... |
| CVE-2021-33604 | LOW | 2.5 | 0.3% | Jun 24, 2021 | URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 thr... |
| CVE-2021-31412 | MEDIUM | 5.3 | 1.3% | Jun 24, 2021 | Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14... |
| CVE-2021-26585 | MEDIUM | 5.5 | 0.2% | Jun 24, 2021 | A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local d... |
| CVE-2021-25923 | HIGH | 8.1 | 1.3% | Jun 24, 2021 | In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum pass... |
| CVE-2021-21737 | HIGH | 7.5 | 0.8% | Jun 24, 2021 | A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection ... |
| CVE-2021-25656 | MEDIUM | 5.4 | 0.3% | Jun 24, 2021 | Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now