2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21202HIGH8.6Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install ...
CVE-2021-21201CRITICAL9.6Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the r...
CVE-2021-20546MEDIUM5.5IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper ...
CVE-2021-20536MEDIUM6.2IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files tha...
CVE-2021-20532HIGH7.8IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full ...
CVE-2021-20432MEDIUM6.5IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker ...
CVE-2021-27851MEDIUM5.5A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-u...
CVE-2021-23382HIGH7.5The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() ...
CVE-2021-3494MEDIUM5.9A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause ...
CVE-2021-3472HIGH7.8A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead...
CVE-2021-28399MEDIUM5.3OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password f...
CVE-2021-25839CRITICAL9.8A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could l...
CVE-2021-25838MEDIUM6.1The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-...
CVE-2021-31802HIGH8.8NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without au...
CVE-2021-28079MEDIUM6.1Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the E...
CVE-2021-26797CRITICAL9.8An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administr...
CVE-2021-25928CRITICAL9.8Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of ser...
CVE-2021-25927CRITICAL9.8Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of se...
CVE-2021-23365CRITICAL9.1The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the ...
CVE-2021-31804MEDIUM5.5LeoCAD before 21.03 sometimes allows a use-after-free during the opening of a new document.
CVE-2021-31803MEDIUM6.1cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
CVE-2021-20712MEDIUM5.3Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware V...
CVE-2021-20711CRITICAL9.8Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors...
CVE-2021-20710MEDIUM6.1Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an ...
CVE-2021-20709HIGH7.2Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now