2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24598 | MEDIUM | 4.8 | 0.7% | Nov 17, 2021 | The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege u... |
| CVE-2021-43337 | MEDIUM | 6.5 | 1.2% | Nov 17, 2021 | SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_scrip... |
| CVE-2021-26337 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address ... |
| CVE-2021-26336 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result... |
| CVE-2021-26330 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources. |
| CVE-2021-26327 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality. |
| CVE-2021-26325 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of ... |
| CVE-2021-26321 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of s... |
| CVE-2021-26320 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local... |
| CVE-2021-41258 | MEDIUM | 5.4 | 0.8% | Nov 16, 2021 | Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each b... |
| CVE-2021-41252 | MEDIUM | 5.4 | 0.9% | Nov 16, 2021 | Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. U... |
| CVE-2021-26329 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result ... |
| CVE-2021-26312 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device ... |
| CVE-2021-38949 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local u... |
| CVE-2021-38882 | MEDIUM | 4.4 | 0.2% | Nov 16, 2021 | IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records befo... |
| CVE-2021-25984 | MEDIUM | 6.1 | 0.7% | Nov 16, 2021 | In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.3 to v1.8.30, are vulnerable to stored Cross-Site S... |
| CVE-2021-25983 | MEDIUM | 6.1 | 0.7% | Nov 16, 2021 | In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.8 to v1.8.30, are vulnerable to reflected Cross-Sit... |
| CVE-2021-25982 | MEDIUM | 6.1 | 0.7% | Nov 16, 2021 | In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site ... |
| CVE-2021-42337 | MEDIUM | 4.3 | 0.9% | Nov 16, 2021 | The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general us... |
| CVE-2021-41271 | MEDIUM | 5.3 | 0.9% | Nov 15, 2021 | Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an erro... |
| CVE-2021-42376 | MEDIUM | 5.5 | 0.4% | Nov 15, 2021 | A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, ... |
| CVE-2021-42375 | MEDIUM | 5.5 | 0.4% | Nov 15, 2021 | An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted ... |
| CVE-2021-42374 | MEDIUM | 5.3 | 0.6% | Nov 15, 2021 | An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-... |
| CVE-2021-42373 | MEDIUM | 5.5 | 0.4% | Nov 15, 2021 | A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no pag... |
| CVE-2021-39222 | MEDIUM | 6.1 | 1.1% | Nov 15, 2021 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a store... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now