Skip to main content

Year archive

CVEs published in 2021

Archive summary

20,149 CVEs published in 2021 — 2,558 Critical, 8,477 High, 8,471 Medium, 643 Low, 0 Unrated.

CVE-2020-16021

Published Jan 8, 2021

Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level privilege escalation…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16020

Published Jan 8, 2021

Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16019

Published Jan 8, 2021

Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16018

Published Jan 8, 2021

Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-16017

Published Jan 8, 2021

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape…

CVSS 9.6 · Critical
evidence mentions
5
Buzz score
50.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-16016

Published Jan 8, 2021

Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-16015

Published Jan 8, 2021

Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16014

Published Jan 8, 2021

Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cra…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-16013

Published Jan 8, 2021

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
6
Buzz score
57.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-16012

Published Jan 8, 2021

Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28208

Published Jan 8, 2021

An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35131

Published Jan 8, 2021

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-5805

Published Jan 8, 2021

In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5804

Published Jan 8, 2021

Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of the GWTTestServiceImpl class lacks proper validation of a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3111

Published Jan 8, 2021

The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 19,851-19,875 of 20,149 CVEsPage 795 of 806