2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45839MEDIUM6.5It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4....
CVE-2021-45837CRITICAL9.8It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by send...
CVE-2021-45836HIGH8.8An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141...
CVE-2021-36628Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-40680. Reason: This candidate is a reservation d...
CVE-2021-40680HIGH8.1There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30...
CVE-2021-4212MEDIUM6.7A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook model...
CVE-2021-4211MEDIUM6.7A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, Think...
CVE-2021-4210MEDIUM6.7A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and...
CVE-2021-3972MEDIUM6.7A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS t...
CVE-2021-3971MEDIUM6.7A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices...
CVE-2021-3970MEDIUM6.7A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BI...
CVE-2021-3898MEDIUM6.5Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify ...
CVE-2021-3897CRITICAL9.8An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) ...
CVE-2021-3849CRITICAL9.8An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) an...
CVE-2021-3722MEDIUM5A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configu...
CVE-2021-3721MEDIUM5.5A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an att...
CVE-2021-38946MEDIUM5.4IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2021-38905MEDIUM4.3IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should ...
CVE-2021-38904MEDIUM6.5IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browse...
CVE-2021-38903MEDIUM5.4IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of ...
CVE-2021-38886HIGH8.8IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacke...
CVE-2021-29824MEDIUM4.3IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could ha...
CVE-2021-20464MEDIUM6.5IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb atta...
CVE-2021-36203CRITICAL9.1The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially craf...
CVE-2021-32929HIGH8.8All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now