2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-46873MEDIUM5.3WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be abl...
CVE-2021-21395MEDIUM4.3Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior...
CVE-2021-36686MEDIUM5.4Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api...
CVE-2021-36539MEDIUM6.5Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the Doc...
CVE-2021-43448MEDIUM5.3ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allo...
CVE-2021-43446MEDIUM6.1ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the docume...
CVE-2021-24837MEDIUM5.4The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow user...
CVE-2021-33642MEDIUM5.5When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function.
CVE-2021-39089MEDIUM6.5IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive inform...
CVE-2021-39011MEDIUM4.9 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that ...
CVE-2021-37499MEDIUM6.5CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View Lice...
CVE-2021-37498MEDIUM6.5An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers...
CVE-2021-4314MEDIUM5.3It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT to...
CVE-2021-36647MEDIUM4.7Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS ...
CVE-2021-4312MEDIUM6.1** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in Th3-822 Rapidleech. This aff...
CVE-2021-46872MEDIUM6.1An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other pr...
CVE-2021-46795MEDIUM4.7A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the T...
CVE-2021-46791MEDIUM5.5Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted ...
CVE-2021-46768MEDIUM5.5Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP...
CVE-2021-46767MEDIUM6.1Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory...
CVE-2021-26407MEDIUM5.5A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting i...
CVE-2021-26404MEDIUM5.5Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential informa...
CVE-2021-26403MEDIUM6.5Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in comp...
CVE-2021-26396MEDIUM4.4Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity ...
CVE-2021-26355MEDIUM5.5Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now