2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43066 | HIGH | 7.8 | 0.2% | May 11, 2022 | A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below,... |
| CVE-2021-3611 | MEDIUM | 6.5 | 0.5% | May 11, 2022 | A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use t... |
| CVE-2021-39059 | MEDIUM | 5.4 | 0.4% | May 11, 2022 | IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. ... |
| CVE-2021-38969 | CRITICAL | 9.8 | 0.7% | May 11, 2022 | IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of suppo... |
| CVE-2021-44167 | HIGH | 7.5 | 0.5% | May 11, 2022 | An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 ... |
| CVE-2021-43081 | MEDIUM | 6.1 | 0.8% | May 11, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below... |
| CVE-2021-42651 | HIGH | 8.8 | 1.5% | May 11, 2022 | A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated ... |
| CVE-2021-37851 | HIGH | 7.8 | 0.2% | May 11, 2022 | Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair featu... |
| CVE-2021-34606 | HIGH | 7.3 | 0.4% | May 11, 2022 | A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, l... |
| CVE-2021-34605 | HIGH | 7.3 | 2.3% | May 11, 2022 | A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitra... |
| CVE-2021-3254 | HIGH | 7.5 | 1.7% | May 11, 2022 | Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap. |
| CVE-2021-39738 | HIGH | 7.8 | 0.1% | May 10, 2022 | In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This co... |
| CVE-2021-39700 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results.... |
| CVE-2021-39670 | MEDIUM | 5.5 | 0.2% | May 10, 2022 | In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation... |
| CVE-2021-46771 | HIGH | 7.8 | 0.3% | May 10, 2022 | Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrar... |
| CVE-2021-43010 | HIGH | 7.5 | 1.0% | May 10, 2022 | In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensit... |
| CVE-2021-26408 | HIGH | 7.1 | 0.3% | May 10, 2022 | Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potent... |
| CVE-2021-26390 | MEDIUM | 6.2 | 0.2% | May 10, 2022 | A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to... |
| CVE-2021-26370 | HIGH | 7.1 | 0.2% | May 10, 2022 | Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious... |
| CVE-2021-26353 | HIGH | 7.8 | 0.3% | May 10, 2022 | Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partiall... |
| CVE-2021-26352 | MEDIUM | 5.5 | 0.2% | May 10, 2022 | Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to inval... |
| CVE-2021-26332 | HIGH | 7.1 | 0.2% | May 10, 2022 | Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availabili... |
| CVE-2021-26324 | HIGH | 7.8 | 0.3% | May 10, 2022 | A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs. |
| CVE-2021-39024 | MEDIUM | 6.1 | 0.4% | May 10, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2021-43094 | CRITICAL | 9.8 | 1.2% | May 10, 2022 | An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now