2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30535 | HIGH | 8.8 | 1.1% | Jun 7, 2021 | Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corrupti... |
| CVE-2021-30534 | MEDIUM | 6.5 | 1.2% | Jun 7, 2021 | Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to byp... |
| CVE-2021-30533 | MEDIUM | 6.5 | 16.6% | Jun 7, 2021 | Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypa... |
| CVE-2021-30532 | MEDIUM | 4.3 | 1.2% | Jun 7, 2021 | Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac... |
| CVE-2021-30531 | MEDIUM | 6.5 | 1.7% | Jun 7, 2021 | Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac... |
| CVE-2021-30530 | HIGH | 8.8 | 1.2% | Jun 7, 2021 | Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out ... |
| CVE-2021-30529 | HIGH | 8.8 | 1.0% | Jun 7, 2021 | Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a... |
| CVE-2021-30528 | HIGH | 8.8 | 1.3% | Jun 7, 2021 | Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had ... |
| CVE-2021-30527 | HIGH | 8.8 | 1.0% | Jun 7, 2021 | Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a mal... |
| CVE-2021-30526 | HIGH | 8.8 | 1.0% | Jun 7, 2021 | Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to insta... |
| CVE-2021-30525 | HIGH | 8.8 | 0.9% | Jun 7, 2021 | Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a... |
| CVE-2021-30524 | HIGH | 8.8 | 1.0% | Jun 7, 2021 | Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a ... |
| CVE-2021-30523 | HIGH | 8.8 | 1.1% | Jun 7, 2021 | Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-30522 | HIGH | 8.8 | 1.4% | Jun 7, 2021 | Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap ... |
| CVE-2021-30521 | HIGH | 8.8 | 1.3% | Jun 7, 2021 | Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform ... |
| CVE-2021-33896 | MEDIUM | 5.3 | 1.8% | Jun 7, 2021 | Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded pat... |
| CVE-2021-29621 | MEDIUM | 5.3 | 3.4% | Jun 7, 2021 | Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask... |
| CVE-2021-20699 | CRITICAL | 9.8 | 1.7% | Jun 7, 2021 | Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492... |
| CVE-2021-20698 | CRITICAL | 9.8 | 1.5% | Jun 7, 2021 | Sharp NEC Displays (UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492V... |
| CVE-2021-20517 | HIGH | 8.8 | 1.9% | Jun 7, 2021 | IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse ... |
| CVE-2021-22222 | HIGH | 7.5 | 1.8% | Jun 7, 2021 | Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafte... |
| CVE-2021-33904 | MEDIUM | 6.1 | 10.1% | Jun 7, 2021 | In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The... |
| CVE-2021-29099 | MEDIUM | 5.3 | 0.6% | Jun 7, 2021 | A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially craf... |
| CVE-2021-24344 | MEDIUM | 4.8 | 0.5% | Jun 7, 2021 | The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+... |
| CVE-2021-24343 | MEDIUM | 4.8 | 0.6% | Jun 7, 2021 | The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, l... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now