2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21308CRITICAL9.1PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout syste...
CVE-2021-21302HIGH7.2PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Inject...
CVE-2021-23345MEDIUM5.3All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via t...
CVE-2021-21274MEDIUM6.5Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-21273MEDIUM6.1Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-21298MEDIUM6.5Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vu...
CVE-2021-21297MEDIUM6.5Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains...
CVE-2021-23979HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corru...
CVE-2021-23978HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evi...
CVE-2021-23965HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corru...
CVE-2021-23964HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evi...
CVE-2021-3010MEDIUM5.4There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server...
CVE-2021-26904CRITICAL9.8LMA ISIDA Retriever 5.2 allows SQL Injection.
CVE-2021-26903MEDIUM6.1LMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text'].
CVE-2021-22661HIGH7.5Changing the password on the module webpage does not require the user to type in the current password first. Thus, the p...
CVE-2021-23977MEDIUM5.3Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read...
CVE-2021-23963MEDIUM4.3When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user in...
CVE-2021-23962HIGH8.8Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable cras...
CVE-2021-23961HIGH7.4Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an in...
CVE-2021-23960HIGH8.8Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exp...
CVE-2021-23959MEDIUM6.1An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the addre...
CVE-2021-23958MEDIUM6.5The browser could have been confused into transferring a screen sharing state into another tab, which would leak uninten...
CVE-2021-23957HIGH7.4Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: Thi...
CVE-2021-23956MEDIUM6.5An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading...
CVE-2021-23955MEDIUM6.1The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now