2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23954HIGH8.8Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading ...
CVE-2021-23953MEDIUM4.3If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin informatio...
CVE-2021-21724MEDIUM4.4A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scena...
CVE-2021-21330MEDIUM6.1aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is...
CVE-2021-23976HIGH8.1When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file ...
CVE-2021-23975MEDIUM6.5The developer page about:memory has a Measure function for exploring what object types the browser has allocated and the...
CVE-2021-23974MEDIUM6.1The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to b...
CVE-2021-23973MEDIUM6.5When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the conten...
CVE-2021-23972HIGH8.8One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com...
CVE-2021-23971MEDIUM6.5When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy...
CVE-2021-23970MEDIUM6.5Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm...
CVE-2021-23969MEDIUM4.3As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure tha...
CVE-2021-23968MEDIUM4.3If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported...
CVE-2021-21328MEDIUM5.3Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps ...
CVE-2021-26701HIGH8.1.NET Core Remote Code Execution Vulnerability
CVE-2021-26700HIGH7.8Visual Studio Code npm-script Extension Remote Code Execution Vulnerability
CVE-2021-25195HIGH7.8Windows PKU2U Elevation of Privilege Vulnerability
CVE-2021-24114MEDIUM5.7Microsoft Teams iOS Information Disclosure Vulnerability
CVE-2021-24113MEDIUM5.4Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2021-24112HIGH8.1.NET Core Remote Code Execution Vulnerability
CVE-2021-24111HIGH7.5.NET Framework Denial of Service Vulnerability
CVE-2021-24109MEDIUM6.8Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2021-24106MEDIUM5.5Windows DirectX Information Disclosure Vulnerability
CVE-2021-24105HIGH8.4<p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package i...
CVE-2021-24103HIGH7.8Windows Event Tracing Elevation of Privilege Vulnerability

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now