2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27772MEDIUM6.5Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users...
CVE-2021-27771HIGH7.6User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. W...
CVE-2021-27770HIGH8.8The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then reque...
CVE-2021-27769MEDIUM5.3Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. ...
CVE-2021-27768MEDIUM5.9Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensiti...
CVE-2021-27500HIGH7.5A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb ...
CVE-2021-27498HIGH7.5A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb ...
CVE-2021-27482HIGH7.5A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb ...
CVE-2021-27478HIGH7.5A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb ...
CVE-2021-26386HIGH7.8A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootlo...
CVE-2021-26368MEDIUM4.4Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser priv...
CVE-2021-26363MEDIUM4.4A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to on...
CVE-2021-26317HIGH7.8Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a ...
CVE-2021-22531MEDIUM6.1A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scrip...
CVE-2021-26369HIGH7.8A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, res...
CVE-2021-26366HIGH7.1An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulti...
CVE-2021-26362HIGH7.1A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapp...
CVE-2021-26361MEDIUM5.5A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate...
CVE-2021-26351MEDIUM5.5Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/wri...
CVE-2021-40399HIGH7.8An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.1035...
CVE-2021-33149MEDIUM5.5Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable informa...
CVE-2021-33135MEDIUM5.5Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potent...
CVE-2021-33130MEDIUM4.6Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an...
CVE-2021-33124MEDIUM6.7Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to po...
CVE-2021-33123HIGH7.8Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now