CVEs from 2021

4,791 normalized CVEs published or assigned in this year.

Total
4,791
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.4%
% with exploit
5.3%

Top products

  • simatic_wincc_runtime_advanced 28
  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • primavera_unifier 8
  • modicon_m340_bmxp342020 8
  • log4j 8
  • mbed_tls 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-38001 high 8.0 Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-38008 high 8.0 Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-23997 high 8.0 Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effort this could have been exploited to run arbitrary …
CVE-2021-38012 high 8.0 Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-24000 high 8.0 A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements…
CVE-2021-38020 high 8.0 Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2021-29952 high 8.0 When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnera…
CVE-2021-4058 high 8.0 Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4054 high 8.0 Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVE-2021-29959 high 8.0 When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only…
CVE-2021-29960 high 8.0 Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined …
CVE-2021-4064 high 8.0 Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-29962 high 8.0 Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnera…
CVE-2021-29961 high 8.0 When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89.
CVE-2021-29963 high 8.0 Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnera…
CVE-2021-29974 high 8.0 When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Stric…
CVE-2021-29965 high 8.0 A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the currently active website instead of the website that…
CVE-2021-29973 high 8.0 Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be ente…
CVE-2021-29975 high 8.0 Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly…
CVE-2021-29987 high 8.0 After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location,…
CVE-2021-29990 high 8.0 Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of thes…
CVE-2021-3655 high 8.0 A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
CVE-2021-38300 high 8.0 arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel co…
CVE-2021-42327 high 8.0 dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to th…
CVE-2021-22166 high 8.0 multiple issues in gitlab
CVE-2021-23965 high 8.0 Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
CVE-2021-30612 high 8.0 Chromium: CVE-2021-30612 Use after free in WebRTC
CVE-2021-30508 high 8.0 Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to enable certain features in Chrome to potentially exploit heap corruption via a …
CVE-2021-30520 high 8.0 Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML…
CVE-2021-30523 high 8.0 Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
CVE-2021-26925 high 8.0 Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
CVE-2021-30543 high 8.0 Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML …
CVE-2021-39889 high 8.0 multiple issues in gitlab
CVE-2021-39912 high 8.0 multiple issues in gitlab
CVE-2021-39913 high 8.0 multiple issues in gitlab
CVE-2021-39934 high 8.0 multiple issues in gitlab
CVE-2021-39936 high 8.0 multiple issues in gitlab
CVE-2021-39933 high 8.0 multiple issues in gitlab
CVE-2021-39932 high 8.0 multiple issues in gitlab
CVE-2021-39931 high 8.0 multiple issues in gitlab
CVE-2021-39917 high 8.0 multiple issues in gitlab
CVE-2021-42322 high 8.0 multiple issues in code
CVE-2021-39941 high 8.0 multiple issues in gitlab
CVE-2021-39915 high 8.0 multiple issues in gitlab
CVE-2021-39945 high 8.0 multiple issues in gitlab
CVE-2021-39906 high 8.0 multiple issues in gitlab
CVE-2021-39897 high 8.0 multiple issues in gitlab
CVE-2021-39909 high 8.0 multiple issues in gitlab
CVE-2021-39898 high 8.0 multiple issues in gitlab
CVE-2021-39905 high 8.0 multiple issues in gitlab
CVE-2021-39895 high 8.0 multiple issues in gitlab
CVE-2021-39907 high 8.0 multiple issues in gitlab
CVE-2021-39903 high 8.0 multiple issues in gitlab
CVE-2021-39902 high 8.0 multiple issues in gitlab
CVE-2021-39914 high 8.0 multiple issues in gitlab
CVE-2021-39875 high 8.0 multiple issues in gitlab
CVE-2021-39873 high 8.0 multiple issues in gitlab
CVE-2021-39872 high 8.0 multiple issues in gitlab
CVE-2021-39891 high 8.0 multiple issues in gitlab
CVE-2021-39887 high 8.0 multiple issues in gitlab
CVE-2021-39886 high 8.0 multiple issues in gitlab
CVE-2021-39879 high 8.0 multiple issues in gitlab
CVE-2021-37960 high 8.0 multiple issues in chromium
CVE-2021-39890 high 8.0 multiple issues in gitlab
CVE-2021-39878 high 8.0 multiple issues in gitlab
CVE-2021-39874 high 8.0 multiple issues in gitlab
CVE-2021-39866 high 8.0 multiple issues in gitlab
CVE-2021-39883 high 8.0 multiple issues in gitlab
CVE-2021-26434 high 8.0 multiple issues in code
CVE-2021-41387 high 8.0 seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.
CVE-2021-39175 high 8.0 cross-site scripting in hedgedoc
CVE-2021-32777 high 8.0 multiple issues in istio
CVE-2021-30631 high 8.0 arbitrary code execution in chromium
CVE-2021-22216 high 8.0 multiple issues in gitlab
CVE-2021-22213 high 8.0 multiple issues in gitlab
CVE-2021-32654 high 8.0 multiple issues in nextcloud
CVE-2021-22220 high 8.0 multiple issues in gitlab
CVE-2021-22221 high 8.0 multiple issues in gitlab
CVE-2021-22218 high 8.0 multiple issues in gitlab
CVE-2021-22214 high 8.0 multiple issues in gitlab
CVE-2021-32778 high 8.0 multiple issues in istio
CVE-2021-22219 high 8.0 multiple issues in gitlab
CVE-2021-22236 high 8.0 multiple issues in gitlab
CVE-2021-22181 high 8.0 multiple issues in gitlab
CVE-2021-32653 high 8.0 multiple issues in nextcloud
CVE-2021-22915 high 8.0 multiple issues in nextcloud
CVE-2021-22237 high 8.0 multiple issues in gitlab
CVE-2021-28457 high 8.0 arbitrary code execution in code
CVE-2021-28471 high 8.0 arbitrary code execution in code
CVE-2021-28477 high 8.0 arbitrary code execution in code
CVE-2021-3557 high 8.0 information disclosure in argocd
CVE-2021-32688 high 8.0 multiple issues in nextcloud
CVE-2021-28473 high 8.0 arbitrary code execution in code
CVE-2021-28469 high 8.0 arbitrary code execution in code
CVE-2021-22230 high 8.0 multiple issues in gitlab
CVE-2021-22223 high 8.0 multiple issues in gitlab
CVE-2021-22225 high 8.0 multiple issues in gitlab
CVE-2021-22229 high 8.0 multiple issues in gitlab
CVE-2021-32741 high 8.0 multiple issues in nextcloud
CVE-2021-32733 high 8.0 multiple issues in nextcloud