2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27772 | MEDIUM | 6.5 | 0.6% | May 12, 2022 | Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users... |
| CVE-2021-27771 | HIGH | 7.6 | 0.7% | May 12, 2022 | User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. W... |
| CVE-2021-27770 | HIGH | 8.8 | 0.7% | May 12, 2022 | The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then reque... |
| CVE-2021-27769 | MEDIUM | 5.3 | 0.7% | May 12, 2022 | Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. ... |
| CVE-2021-27768 | MEDIUM | 5.9 | 0.3% | May 12, 2022 | Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensiti... |
| CVE-2021-27500 | HIGH | 7.5 | 1.2% | May 12, 2022 | A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb ... |
| CVE-2021-27498 | HIGH | 7.5 | 1.2% | May 12, 2022 | A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb ... |
| CVE-2021-27482 | HIGH | 7.5 | 1.2% | May 12, 2022 | A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb ... |
| CVE-2021-27478 | HIGH | 7.5 | 1.0% | May 12, 2022 | A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb ... |
| CVE-2021-26386 | HIGH | 7.8 | 0.3% | May 12, 2022 | A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootlo... |
| CVE-2021-26368 | MEDIUM | 4.4 | 0.1% | May 12, 2022 | Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser priv... |
| CVE-2021-26363 | MEDIUM | 4.4 | 0.2% | May 12, 2022 | A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to on... |
| CVE-2021-26317 | HIGH | 7.8 | 0.3% | May 12, 2022 | Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a ... |
| CVE-2021-22531 | MEDIUM | 6.1 | 0.5% | May 12, 2022 | A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scrip... |
| CVE-2021-26369 | HIGH | 7.8 | 0.2% | May 12, 2022 | A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, res... |
| CVE-2021-26366 | HIGH | 7.1 | 0.2% | May 12, 2022 | An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulti... |
| CVE-2021-26362 | HIGH | 7.1 | 0.2% | May 12, 2022 | A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapp... |
| CVE-2021-26361 | MEDIUM | 5.5 | 0.2% | May 12, 2022 | A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate... |
| CVE-2021-26351 | MEDIUM | 5.5 | 0.2% | May 12, 2022 | Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/wri... |
| CVE-2021-40399 | HIGH | 7.8 | 1.2% | May 12, 2022 | An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.1035... |
| CVE-2021-33149 | MEDIUM | 5.5 | 0.2% | May 12, 2022 | Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable informa... |
| CVE-2021-33135 | MEDIUM | 5.5 | 0.3% | May 12, 2022 | Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potent... |
| CVE-2021-33130 | MEDIUM | 4.6 | 0.2% | May 12, 2022 | Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an... |
| CVE-2021-33124 | MEDIUM | 6.7 | 0.2% | May 12, 2022 | Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to po... |
| CVE-2021-33123 | HIGH | 7.8 | 0.3% | May 12, 2022 | Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now