2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21202 | HIGH | 8.6 | 1.0% | Apr 26, 2021 | Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install ... |
| CVE-2021-21201 | CRITICAL | 9.6 | 1.7% | Apr 26, 2021 | Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the r... |
| CVE-2021-20546 | MEDIUM | 5.5 | 0.3% | Apr 26, 2021 | IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper ... |
| CVE-2021-20536 | MEDIUM | 6.2 | 0.3% | Apr 26, 2021 | IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files tha... |
| CVE-2021-20532 | HIGH | 7.8 | 0.2% | Apr 26, 2021 | IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full ... |
| CVE-2021-20432 | MEDIUM | 6.5 | 0.7% | Apr 26, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker ... |
| CVE-2021-27851 | MEDIUM | 5.5 | 0.3% | Apr 26, 2021 | A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-u... |
| CVE-2021-23382 | HIGH | 7.5 | 2.5% | Apr 26, 2021 | The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() ... |
| CVE-2021-3494 | MEDIUM | 5.9 | 0.4% | Apr 26, 2021 | A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause ... |
| CVE-2021-3472 | HIGH | 7.8 | 1.1% | Apr 26, 2021 | A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead... |
| CVE-2021-28399 | MEDIUM | 5.3 | 1.0% | Apr 26, 2021 | OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password f... |
| CVE-2021-25839 | CRITICAL | 9.8 | 1.2% | Apr 26, 2021 | A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could l... |
| CVE-2021-25838 | MEDIUM | 6.1 | 0.6% | Apr 26, 2021 | The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-... |
| CVE-2021-31802 | HIGH | 8.8 | 14.2% | Apr 26, 2021 | NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without au... |
| CVE-2021-28079 | MEDIUM | 6.1 | 1.2% | Apr 26, 2021 | Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the E... |
| CVE-2021-26797 | CRITICAL | 9.8 | 1.4% | Apr 26, 2021 | An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administr... |
| CVE-2021-25928 | CRITICAL | 9.8 | 3.3% | Apr 26, 2021 | Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of ser... |
| CVE-2021-25927 | CRITICAL | 9.8 | 3.3% | Apr 26, 2021 | Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of se... |
| CVE-2021-23365 | CRITICAL | 9.1 | 1.0% | Apr 26, 2021 | The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the ... |
| CVE-2021-31804 | MEDIUM | 5.5 | 0.8% | Apr 26, 2021 | LeoCAD before 21.03 sometimes allows a use-after-free during the opening of a new document. |
| CVE-2021-31803 | MEDIUM | 6.1 | 0.6% | Apr 26, 2021 | cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581). |
| CVE-2021-20712 | MEDIUM | 5.3 | 0.8% | Apr 26, 2021 | Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware V... |
| CVE-2021-20711 | CRITICAL | 9.8 | 1.4% | Apr 26, 2021 | Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors... |
| CVE-2021-20710 | MEDIUM | 6.1 | 0.8% | Apr 26, 2021 | Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an ... |
| CVE-2021-20709 | HIGH | 7.2 | 0.7% | Apr 26, 2021 | Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now