2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24598MEDIUM4.8The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege u...
CVE-2021-43337MEDIUM6.5SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_scrip...
CVE-2021-26337MEDIUM5.5Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address ...
CVE-2021-26336MEDIUM5.5Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result...
CVE-2021-26330MEDIUM5.5AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
CVE-2021-26327MEDIUM5.5Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.
CVE-2021-26325MEDIUM5.5Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of ...
CVE-2021-26321MEDIUM5.5Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of s...
CVE-2021-26320MEDIUM5.5Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local...
CVE-2021-41258MEDIUM5.4Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each b...
CVE-2021-41252MEDIUM5.4Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. U...
CVE-2021-26329MEDIUM5.5AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result ...
CVE-2021-26312MEDIUM5.5Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device ...
CVE-2021-38949MEDIUM5.5IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local u...
CVE-2021-38882MEDIUM4.4IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records befo...
CVE-2021-25984MEDIUM6.1In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.3 to v1.8.30, are vulnerable to stored Cross-Site S...
CVE-2021-25983MEDIUM6.1In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.8 to v1.8.30, are vulnerable to reflected Cross-Sit...
CVE-2021-25982MEDIUM6.1In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site ...
CVE-2021-42337MEDIUM4.3The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general us...
CVE-2021-41271MEDIUM5.3Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an erro...
CVE-2021-42376MEDIUM5.5A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, ...
CVE-2021-42375MEDIUM5.5An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted ...
CVE-2021-42374MEDIUM5.3An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-...
CVE-2021-42373MEDIUM5.5A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no pag...
CVE-2021-39222MEDIUM6.1Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a store...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now