CVEs from 2021

5,048 normalized CVEs published or assigned in this year.

Total
5,048
critical
critical 273
high
high 975
medium
medium 1,141
low
low 135
% Critical
5.4%
% with KEV
4.2%
% with exploit
4.2%

Top products

  • office 13
  • 365_apps 6
  • office_long_term_servicing_channel 6
  • library_automation_system 5
  • single_connect 4
  • http_server 3
  • solidfire 2
  • student_information_management_system 2
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2021-22171 high 8.0 multiple issues in gitlab arch
CVE-2021-23983 high 8.0 By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vul… archsusedebian
CVE-2021-38012 high 8.0 multiple issues in chromium archdebian
CVE-2021-23988 high 8.0 Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl… archsusedebian
CVE-2021-4062 high 8.0 multiple issues in chromium archdebian
CVE-2021-3570 high 8.0 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or pote… suserockylinuxdebian
CVE-2021-30630 high 8.0 arbitrary code execution in chromium archdebian
CVE-2021-21163 high 8.0 Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server. archdebian
CVE-2021-22213 high 8.0 multiple issues in gitlab arch
CVE-2021-22216 high 8.0 multiple issues in gitlab arch
CVE-2021-21161 high 8.0 Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2021-29970 high 8.0 A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerabili… archsusedebianrockylinux
CVE-2021-30626 high 8.0 arbitrary code execution in chromium archdebian
CVE-2021-30625 high 8.0 arbitrary code execution in chromium archdebian
CVE-2021-38013 high 8.0 multiple issues in chromium archdebian
CVE-2021-23970 high 8.0 Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability affects Firefox < 86. archsusedebian
CVE-2021-28457 high 8.0 arbitrary code execution in code arch
CVE-2021-22236 high 8.0 multiple issues in gitlab arch
CVE-2021-4067 high 8.0 multiple issues in chromium archdebian
CVE-2021-38008 high 8.0 multiple issues in chromium archdebian
CVE-2021-4052 high 8.0 multiple issues in chromium archdebian
CVE-2021-38494 high 8.0 Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl… archdebian
CVE-2021-29972 high 8.0 A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilit… archsusedebian
CVE-2021-4057 high 8.0 multiple issues in chromium archdebian
CVE-2021-21208 high 8.0 Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain spoofing via a crafted QR code. archdebian
CVE-2021-37997 high 8.0 multiple issues in chromium archdebian
CVE-2021-43540 high 8.0 WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension. This vulnerability affects … archsusedebian
CVE-2021-22890 high 8.0 curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.… archdebiansuse
CVE-2021-39875 high 8.0 multiple issues in gitlab arch
CVE-2021-32734 high 8.0 multiple issues in nextcloud arch
CVE-2021-22217 high 8.0 multiple issues in gitlab arch
CVE-2021-39888 high 8.0 multiple issues in gitlab arch
CVE-2021-21216 high 8.0 Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page. archdebian
CVE-2021-30631 high 8.0 arbitrary code execution in chromium arch
CVE-2021-37994 high 8.0 multiple issues in chromium archdebian
CVE-2021-38007 high 8.0 multiple issues in chromium archdebian
CVE-2021-22915 high 8.0 multiple issues in nextcloud arch
CVE-2021-32653 high 8.0 multiple issues in nextcloud arch
CVE-2021-22219 high 8.0 multiple issues in gitlab arch
CVE-2021-22206 high 8.0 multiple issues in gitlab arch
CVE-2021-26925 high 8.0 Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering. archdebian
CVE-2021-28477 high 8.0 arbitrary code execution in code arch
CVE-2021-32688 high 8.0 multiple issues in nextcloud arch
CVE-2021-22230 high 8.0 multiple issues in gitlab arch
CVE-2021-30525 high 8.0 multiple issues in chromium archdebian
CVE-2021-26910 high 8.0 Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation. archdebian
CVE-2021-37963 high 8.0 Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page. archdebian
CVE-2021-30590 high 8.0 multiple issues in chromium archdebian
CVE-2021-30576 high 8.0 multiple issues in chromium archdebian
CVE-2021-30532 high 8.0 multiple issues in chromium archdebian
CVE-2021-1051 high 8.0 multiple issues in nvidia-utils arch
CVE-2021-21152 high 8.0 Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2021-23985 high 8.0 If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unno… archsusedebian
CVE-2021-38006 high 8.0 multiple issues in chromium archdebian
CVE-2021-37988 high 8.0 multiple issues in chromium archdebian
CVE-2021-21155 high 8.0 Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a c… archdebian
CVE-2021-33582 high 8.0 Important: cyrus-imapd security update debiansuserockylinux
CVE-2021-38022 high 8.0 multiple issues in chromium archdebian
CVE-2021-32751 high 8.0 Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code e… archsusedebian
CVE-2021-23975 high 8.0 The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof funct… archsusedebian
CVE-2021-30535 high 8.0 multiple issues in chromium archdebian
CVE-2021-33833 high 8.0 ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA). archdebiansuse
CVE-2021-23969 high 8.0 As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s no… archsusedebian
CVE-2021-4056 high 8.0 multiple issues in chromium archdebian
CVE-2021-32917 high 8.0 An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use … archdebian
CVE-2021-30575 high 8.0 multiple issues in chromium archdebian
CVE-2021-20247 high 8.0 A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailb… archdebian
CVE-2021-25746 high 8.0 information disclosure in kubectl-ingress-nginx archsuse
CVE-2021-4053 high 8.0 multiple issues in chromium archdebian
CVE-2021-39879 high 8.0 multiple issues in gitlab arch
CVE-2021-39936 high 8.0 multiple issues in gitlab arch
CVE-2021-41259 high 8.0 multiple issues in nim arch
CVE-2021-39932 high 8.0 multiple issues in gitlab arch
CVE-2021-39933 high 8.0 multiple issues in gitlab arch
CVE-2021-39886 high 8.0 multiple issues in gitlab arch
CVE-2021-41524 high 8.0 multiple issues in apache debianarch
CVE-2021-30591 high 8.0 multiple issues in chromium archdebian
CVE-2021-39872 high 8.0 multiple issues in gitlab arch
CVE-2021-39887 high 8.0 multiple issues in gitlab arch
CVE-2021-39891 high 8.0 multiple issues in gitlab arch
CVE-2021-37981 high 8.0 multiple issues in chromium archdebian
CVE-2021-38371 high 8.0 The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending. archdebian
CVE-2021-39175 high 8.0 cross-site scripting in hedgedoc arch
CVE-2021-32777 high 8.0 multiple issues in istio arch
CVE-2021-38020 high 8.0 multiple issues in chromium archdebian
CVE-2021-38019 high 8.0 multiple issues in chromium archdebian
CVE-2021-4061 high 8.0 multiple issues in chromium archdebian
CVE-2021-4058 high 8.0 multiple issues in chromium archdebian
CVE-2021-38017 high 8.0 multiple issues in chromium archdebian
CVE-2021-22218 high 8.0 multiple issues in gitlab arch
CVE-2021-22221 high 8.0 multiple issues in gitlab arch
CVE-2021-22220 high 8.0 multiple issues in gitlab arch
CVE-2021-37993 high 8.0 multiple issues in chromium archdebian
CVE-2021-32778 high 8.0 multiple issues in istio arch
CVE-2021-22181 high 8.0 multiple issues in gitlab arch
CVE-2021-38015 high 8.0 multiple issues in chromium archdebian
CVE-2021-4055 high 8.0 multiple issues in chromium archdebian
CVE-2021-37989 high 8.0 multiple issues in chromium archdebian
CVE-2021-22237 high 8.0 multiple issues in gitlab arch
CVE-2021-28471 high 8.0 arbitrary code execution in code arch