2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23954 | HIGH | 8.8 | 1.1% | Feb 26, 2021 | Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading ... |
| CVE-2021-23953 | MEDIUM | 4.3 | 1.1% | Feb 26, 2021 | If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin informatio... |
| CVE-2021-21724 | MEDIUM | 4.4 | 0.4% | Feb 26, 2021 | A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scena... |
| CVE-2021-21330 | MEDIUM | 6.1 | 1.9% | Feb 26, 2021 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is... |
| CVE-2021-23976 | HIGH | 8.1 | 1.1% | Feb 26, 2021 | When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file ... |
| CVE-2021-23975 | MEDIUM | 6.5 | 1.0% | Feb 26, 2021 | The developer page about:memory has a Measure function for exploring what object types the browser has allocated and the... |
| CVE-2021-23974 | MEDIUM | 6.1 | 0.8% | Feb 26, 2021 | The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to b... |
| CVE-2021-23973 | MEDIUM | 6.5 | 1.4% | Feb 26, 2021 | When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the conten... |
| CVE-2021-23972 | HIGH | 8.8 | 1.0% | Feb 26, 2021 | One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com... |
| CVE-2021-23971 | MEDIUM | 6.5 | 1.0% | Feb 26, 2021 | When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy... |
| CVE-2021-23970 | MEDIUM | 6.5 | 1.0% | Feb 26, 2021 | Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm... |
| CVE-2021-23969 | MEDIUM | 4.3 | 1.2% | Feb 26, 2021 | As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure tha... |
| CVE-2021-23968 | MEDIUM | 4.3 | 1.2% | Feb 26, 2021 | If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported... |
| CVE-2021-21328 | MEDIUM | 5.3 | 1.6% | Feb 26, 2021 | Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps ... |
| CVE-2021-26701 | HIGH | 8.1 | 30.3% | Feb 25, 2021 | .NET Core Remote Code Execution Vulnerability |
| CVE-2021-26700 | HIGH | 7.8 | 6.0% | Feb 25, 2021 | Visual Studio Code npm-script Extension Remote Code Execution Vulnerability |
| CVE-2021-25195 | HIGH | 7.8 | 0.6% | Feb 25, 2021 | Windows PKU2U Elevation of Privilege Vulnerability |
| CVE-2021-24114 | MEDIUM | 5.7 | 2.8% | Feb 25, 2021 | Microsoft Teams iOS Information Disclosure Vulnerability |
| CVE-2021-24113 | MEDIUM | 5.4 | 1.3% | Feb 25, 2021 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2021-24112 | HIGH | 8.1 | 3.3% | Feb 25, 2021 | .NET Core Remote Code Execution Vulnerability |
| CVE-2021-24111 | HIGH | 7.5 | 3.8% | Feb 25, 2021 | .NET Framework Denial of Service Vulnerability |
| CVE-2021-24109 | MEDIUM | 6.8 | 2.0% | Feb 25, 2021 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2021-24106 | MEDIUM | 5.5 | 0.9% | Feb 25, 2021 | Windows DirectX Information Disclosure Vulnerability |
| CVE-2021-24105 | HIGH | 8.4 | 2.1% | Feb 25, 2021 | <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package i... |
| CVE-2021-24103 | HIGH | 7.8 | 0.6% | Feb 25, 2021 | Windows Event Tracing Elevation of Privilege Vulnerability |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now