2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42646CRITICAL9.1XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in...
CVE-2021-36614MEDIUM6.5Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An au...
CVE-2021-36613MEDIUM6.5Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticat...
CVE-2021-34085CRITICAL9.8Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows rem...
CVE-2021-33317HIGH7.5The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability...
CVE-2021-33316CRITICAL9.8The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This...
CVE-2021-33315CRITICAL9.8The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This...
CVE-2021-31330MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authen...
CVE-2021-28290MEDIUM6.1A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to t...
CVE-2021-46744MEDIUM6.5An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by mo...
CVE-2021-30361MEDIUM6.7The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients setti...
CVE-2021-26400MEDIUM4AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple ...
CVE-2021-26388MEDIUM5.5Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposin...
CVE-2021-26378MEDIUM5.5Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that coul...
CVE-2021-26376MEDIUM5.5Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resultin...
CVE-2021-26375MEDIUM5.5Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to...
CVE-2021-26373MEDIUM5.5Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could resu...
CVE-2021-26372MEDIUM5.5Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address...
CVE-2021-26364MEDIUM5.5Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM ...
CVE-2021-26350MEDIUM4.7A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register ...
CVE-2021-26349MEDIUM5.5Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into ...
CVE-2021-26348MEDIUM5.5Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device ...
CVE-2021-26347MEDIUM4.7Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an i...
CVE-2021-26342LOW3.3In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of op...
CVE-2021-26339MEDIUM5.5A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now