2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42646 | CRITICAL | 9.1 | 3.7% | May 11, 2022 | XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in... |
| CVE-2021-36614 | MEDIUM | 6.5 | 2.1% | May 11, 2022 | Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An au... |
| CVE-2021-36613 | MEDIUM | 6.5 | 2.1% | May 11, 2022 | Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticat... |
| CVE-2021-34085 | CRITICAL | 9.8 | 1.7% | May 11, 2022 | Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows rem... |
| CVE-2021-33317 | HIGH | 7.5 | 0.9% | May 11, 2022 | The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability... |
| CVE-2021-33316 | CRITICAL | 9.8 | 1.0% | May 11, 2022 | The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This... |
| CVE-2021-33315 | CRITICAL | 9.8 | 1.0% | May 11, 2022 | The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This... |
| CVE-2021-31330 | MEDIUM | 5.4 | 0.8% | May 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authen... |
| CVE-2021-28290 | MEDIUM | 6.1 | 0.6% | May 11, 2022 | A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to t... |
| CVE-2021-46744 | MEDIUM | 6.5 | 0.3% | May 11, 2022 | An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by mo... |
| CVE-2021-30361 | MEDIUM | 6.7 | 4.1% | May 11, 2022 | The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients setti... |
| CVE-2021-26400 | MEDIUM | 4 | 0.2% | May 11, 2022 | AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple ... |
| CVE-2021-26388 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposin... |
| CVE-2021-26378 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that coul... |
| CVE-2021-26376 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resultin... |
| CVE-2021-26375 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to... |
| CVE-2021-26373 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could resu... |
| CVE-2021-26372 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address... |
| CVE-2021-26364 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM ... |
| CVE-2021-26350 | MEDIUM | 4.7 | 0.1% | May 11, 2022 | A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register ... |
| CVE-2021-26349 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into ... |
| CVE-2021-26348 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device ... |
| CVE-2021-26347 | MEDIUM | 4.7 | 0.2% | May 11, 2022 | Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an i... |
| CVE-2021-26342 | LOW | 3.3 | 0.2% | May 11, 2022 | In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of op... |
| CVE-2021-26339 | MEDIUM | 5.5 | 0.3% | May 11, 2022 | A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now