Skip to main content

Year archive

CVEs published in 2021

Archive summary

20,149 CVEs published in 2021 — 2,558 Critical, 8,477 High, 8,471 Medium, 643 Low, 0 Unrated.

CVE-2020-25476

Published Jan 7, 2021

Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. An attacker can insert the mali…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3011

Published Jan 7, 2021

An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2020-28672

Published Jan 7, 2021

MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/category.php:27, user input can be saved to category/[folde…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3029

Published Jan 7, 2021

EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35114

Published Jan 7, 2021

Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26979

Published Jan 7, 2021

When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigati…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26977

Published Jan 7, 2021

By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26976

Published Jan 7, 2021

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26975

Published Jan 7, 2021

When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 19,926-19,950 of 20,149 CVEsPage 798 of 806