2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43066HIGH7.8A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below,...
CVE-2021-3611MEDIUM6.5A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use t...
CVE-2021-39059MEDIUM5.4IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. ...
CVE-2021-38969CRITICAL9.8IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of suppo...
CVE-2021-44167HIGH7.5An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 ...
CVE-2021-43081MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below...
CVE-2021-42651HIGH8.8A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated ...
CVE-2021-37851HIGH7.8Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair featu...
CVE-2021-34606HIGH7.3A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, l...
CVE-2021-34605HIGH7.3A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitra...
CVE-2021-3254HIGH7.5Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.
CVE-2021-39738HIGH7.8In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This co...
CVE-2021-39700MEDIUM5.5In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results....
CVE-2021-39670MEDIUM5.5In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation...
CVE-2021-46771HIGH7.8Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrar...
CVE-2021-43010HIGH7.5In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensit...
CVE-2021-26408HIGH7.1Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potent...
CVE-2021-26390MEDIUM6.2A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to...
CVE-2021-26370HIGH7.1Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious...
CVE-2021-26353HIGH7.8Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partiall...
CVE-2021-26352MEDIUM5.5Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to inval...
CVE-2021-26332HIGH7.1Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availabili...
CVE-2021-26324HIGH7.8A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.
CVE-2021-39024MEDIUM6.1IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2021-43094CRITICAL9.8An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now