LiveActive security incident?Get immediate response
CVE archive

February 2021

Browse CVE records published in February 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2047 matching CVEs · Page 9 of 41.

High · CVSS 8.8

CVE-2021-40420: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1...

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

Published Feb 4, 2022 · Updated Apr 15, 2025

Critical · CVSS 9

CVE-2021-21962: A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Sy...

A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-in-the-middle attack in order to trigger this vulnerability.

Published Feb 4, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.6

CVE-2021-4201: Pre-authentication session hijacking

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all previous versions.

Published Feb 14, 2022 · Updated Apr 14, 2025

Medium · CVSS 5.4

CVE-2021-37373: Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows...

Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.

Published Feb 3, 2023 · Updated Mar 26, 2025

Medium · CVSS 5.4

CVE-2021-37378: Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier al...

Cross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.

Published Feb 3, 2023 · Updated Mar 26, 2025