2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28815MEDIUM4.9Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, t...
CVE-2021-3535MEDIUM6.1Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Fil...
CVE-2021-32685CRITICAL9.8tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signature...
CVE-2021-32676MEDIUM6.5Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Tal...
CVE-2021-32623MEDIUM6.5Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to ...
CVE-2021-30553HIGH8.8Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially explo...
CVE-2021-30552HIGH8.8Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install...
CVE-2021-30551HIGH8.8Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru...
CVE-2021-30550HIGH8.8Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to inst...
CVE-2021-30549HIGH8.8Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to instal...
CVE-2021-30548HIGH8.8Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap c...
CVE-2021-30547HIGH8.8Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform ou...
CVE-2021-30546HIGH8.8Use after free in Autofill in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap...
CVE-2021-30545HIGH8.8Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the r...
CVE-2021-30544HIGH8.8Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap ...
CVE-2021-28858MEDIUM5.5TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monit...
CVE-2021-28857HIGH7.5TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.
CVE-2021-24037CRITICAL9.8A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a...
CVE-2021-3595LOW3.8An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the...
CVE-2021-3594LOW3.8An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the...
CVE-2021-3593LOW3.8An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the...
CVE-2021-3592LOW3.8An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the...
CVE-2021-34170CRITICAL9.8Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.
CVE-2021-34129HIGH8.1LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in ...
CVE-2021-34128HIGH8.8LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=p...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now