2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28815 | MEDIUM | 4.9 | 1.7% | Jun 16, 2021 | Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, t... |
| CVE-2021-3535 | MEDIUM | 6.1 | 0.6% | Jun 16, 2021 | Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Fil... |
| CVE-2021-32685 | CRITICAL | 9.8 | 0.7% | Jun 16, 2021 | tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signature... |
| CVE-2021-32676 | MEDIUM | 6.5 | 1.0% | Jun 16, 2021 | Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Tal... |
| CVE-2021-32623 | MEDIUM | 6.5 | 1.3% | Jun 16, 2021 | Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to ... |
| CVE-2021-30553 | HIGH | 8.8 | 1.2% | Jun 15, 2021 | Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially explo... |
| CVE-2021-30552 | HIGH | 8.8 | 1.0% | Jun 15, 2021 | Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install... |
| CVE-2021-30551 | HIGH | 8.8 | 64.7% | Jun 15, 2021 | Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2021-30550 | HIGH | 8.8 | 0.9% | Jun 15, 2021 | Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to inst... |
| CVE-2021-30549 | HIGH | 8.8 | 0.9% | Jun 15, 2021 | Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to instal... |
| CVE-2021-30548 | HIGH | 8.8 | 1.2% | Jun 15, 2021 | Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap c... |
| CVE-2021-30547 | HIGH | 8.8 | 3.6% | Jun 15, 2021 | Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform ou... |
| CVE-2021-30546 | HIGH | 8.8 | 1.1% | Jun 15, 2021 | Use after free in Autofill in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap... |
| CVE-2021-30545 | HIGH | 8.8 | 1.1% | Jun 15, 2021 | Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the r... |
| CVE-2021-30544 | HIGH | 8.8 | 1.2% | Jun 15, 2021 | Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap ... |
| CVE-2021-28858 | MEDIUM | 5.5 | 0.3% | Jun 15, 2021 | TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monit... |
| CVE-2021-28857 | HIGH | 7.5 | 1.3% | Jun 15, 2021 | TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie. |
| CVE-2021-24037 | CRITICAL | 9.8 | 1.8% | Jun 15, 2021 | A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a... |
| CVE-2021-3595 | LOW | 3.8 | 0.3% | Jun 15, 2021 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the... |
| CVE-2021-3594 | LOW | 3.8 | 0.3% | Jun 15, 2021 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the... |
| CVE-2021-3593 | LOW | 3.8 | 0.3% | Jun 15, 2021 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the... |
| CVE-2021-3592 | LOW | 3.8 | 0.3% | Jun 15, 2021 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the... |
| CVE-2021-34170 | CRITICAL | 9.8 | 3.2% | Jun 15, 2021 | Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code. |
| CVE-2021-34129 | HIGH | 8.1 | 1.7% | Jun 15, 2021 | LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in ... |
| CVE-2021-34128 | HIGH | 8.8 | 1.5% | Jun 15, 2021 | LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=p... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now