2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42726 | HIGH | 7.8 | 2.3% | Nov 16, 2021 | Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a... |
| CVE-2021-26335 | HIGH | 7.8 | 0.3% | Nov 16, 2021 | Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to us... |
| CVE-2021-26331 | HIGH | 7.8 | 0.3% | Nov 16, 2021 | AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox ent... |
| CVE-2021-26323 | HIGH | 7.8 | 0.2% | Nov 16, 2021 | Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity. |
| CVE-2021-26315 | HIGH | 7.8 | 0.2% | Nov 16, 2021 | When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW,... |
| CVE-2021-43046 | HIGH | 8.8 | 1.0% | Nov 16, 2021 | The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an easily exploi... |
| CVE-2021-26338 | HIGH | 7.5 | 0.9% | Nov 16, 2021 | Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control table... |
| CVE-2021-26326 | HIGH | 7.8 | 0.3% | Nov 16, 2021 | Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity. |
| CVE-2021-26322 | HIGH | 7.5 | 1.0% | Nov 16, 2021 | Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”. |
| CVE-2021-42114 | HIGH | 8.3 | 2.9% | Nov 16, 2021 | Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitiga... |
| CVE-2021-25965 | HIGH | 8.8 | 0.5% | Nov 16, 2021 | In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated... |
| CVE-2021-25940 | HIGH | 8 | 0.8% | Nov 16, 2021 | In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is... |
| CVE-2021-25976 | HIGH | 8.1 | 0.4% | Nov 16, 2021 | In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing variou... |
| CVE-2021-42386 | HIGH | 7.2 | 2.6% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42385 | HIGH | 7.2 | 2.7% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42384 | HIGH | 7.2 | 2.6% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42383 | HIGH | 7.2 | 2.1% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42382 | HIGH | 7.2 | 2.6% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42381 | HIGH | 7.2 | 2.7% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42380 | HIGH | 7.2 | 2.9% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42379 | HIGH | 7.2 | 2.7% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42378 | HIGH | 7.2 | 2.6% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-41263 | HIGH | 8.8 | 0.6% | Nov 15, 2021 | rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Ra... |
| CVE-2021-41244 | HIGH | 7.2 | 2.8% | Nov 15, 2021 | Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access c... |
| CVE-2021-38984 | HIGH | 7.5 | 0.6% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now