2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21308 | CRITICAL | 9.1 | 1.0% | Feb 26, 2021 | PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout syste... |
| CVE-2021-21302 | HIGH | 7.2 | 1.4% | Feb 26, 2021 | PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Inject... |
| CVE-2021-23345 | MEDIUM | 5.3 | 1.1% | Feb 26, 2021 | All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via t... |
| CVE-2021-21274 | MEDIUM | 6.5 | 2.2% | Feb 26, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-21273 | MEDIUM | 6.1 | 1.8% | Feb 26, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-21298 | MEDIUM | 6.5 | 1.2% | Feb 26, 2021 | Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vu... |
| CVE-2021-21297 | MEDIUM | 6.5 | 1.4% | Feb 26, 2021 | Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains... |
| CVE-2021-23979 | HIGH | 8.8 | 0.9% | Feb 26, 2021 | Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corru... |
| CVE-2021-23978 | HIGH | 8.8 | 1.5% | Feb 26, 2021 | Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evi... |
| CVE-2021-23965 | HIGH | 8.8 | 1.0% | Feb 26, 2021 | Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corru... |
| CVE-2021-23964 | HIGH | 8.8 | 1.3% | Feb 26, 2021 | Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evi... |
| CVE-2021-3010 | MEDIUM | 5.4 | 0.9% | Feb 26, 2021 | There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server... |
| CVE-2021-26904 | CRITICAL | 9.8 | 2.0% | Feb 26, 2021 | LMA ISIDA Retriever 5.2 allows SQL Injection. |
| CVE-2021-26903 | MEDIUM | 6.1 | 1.0% | Feb 26, 2021 | LMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text']. |
| CVE-2021-22661 | HIGH | 7.5 | 1.0% | Feb 26, 2021 | Changing the password on the module webpage does not require the user to type in the current password first. Thus, the p... |
| CVE-2021-23977 | MEDIUM | 5.3 | 0.9% | Feb 26, 2021 | Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read... |
| CVE-2021-23963 | MEDIUM | 4.3 | 0.7% | Feb 26, 2021 | When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user in... |
| CVE-2021-23962 | HIGH | 8.8 | 0.9% | Feb 26, 2021 | Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable cras... |
| CVE-2021-23961 | HIGH | 7.4 | 1.3% | Feb 26, 2021 | Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an in... |
| CVE-2021-23960 | HIGH | 8.8 | 1.2% | Feb 26, 2021 | Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exp... |
| CVE-2021-23959 | MEDIUM | 6.1 | 0.6% | Feb 26, 2021 | An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the addre... |
| CVE-2021-23958 | MEDIUM | 6.5 | 0.9% | Feb 26, 2021 | The browser could have been confused into transferring a screen sharing state into another tab, which would leak uninten... |
| CVE-2021-23957 | HIGH | 7.4 | 0.8% | Feb 26, 2021 | Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: Thi... |
| CVE-2021-23956 | MEDIUM | 6.5 | 1.0% | Feb 26, 2021 | An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading... |
| CVE-2021-23955 | MEDIUM | 6.1 | 0.7% | Feb 26, 2021 | The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now