2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46873 | MEDIUM | 5.3 | 0.5% | Jan 29, 2023 | WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be abl... |
| CVE-2021-21395 | MEDIUM | 4.3 | 0.4% | Jan 27, 2023 | Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior... |
| CVE-2021-36686 | MEDIUM | 5.4 | 0.5% | Jan 26, 2023 | Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api... |
| CVE-2021-36539 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the Doc... |
| CVE-2021-43448 | MEDIUM | 5.3 | 1.0% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allo... |
| CVE-2021-43446 | MEDIUM | 6.1 | 0.8% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the docume... |
| CVE-2021-24837 | MEDIUM | 5.4 | 0.4% | Jan 23, 2023 | The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow user... |
| CVE-2021-33642 | MEDIUM | 5.5 | 0.2% | Jan 20, 2023 | When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function. |
| CVE-2021-39089 | MEDIUM | 6.5 | 0.7% | Jan 20, 2023 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive inform... |
| CVE-2021-39011 | MEDIUM | 4.9 | 0.6% | Jan 20, 2023 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that ... |
| CVE-2021-37499 | MEDIUM | 6.5 | 0.9% | Jan 20, 2023 | CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View Lice... |
| CVE-2021-37498 | MEDIUM | 6.5 | 0.8% | Jan 20, 2023 | An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers... |
| CVE-2021-4314 | MEDIUM | 5.3 | 0.4% | Jan 18, 2023 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT to... |
| CVE-2021-36647 | MEDIUM | 4.7 | 0.2% | Jan 17, 2023 | Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS ... |
| CVE-2021-4312 | MEDIUM | 6.1 | 0.5% | Jan 13, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in Th3-822 Rapidleech. This aff... |
| CVE-2021-46872 | MEDIUM | 6.1 | 0.5% | Jan 13, 2023 | An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other pr... |
| CVE-2021-46795 | MEDIUM | 4.7 | 0.1% | Jan 11, 2023 | A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the T... |
| CVE-2021-46791 | MEDIUM | 5.5 | 0.2% | Jan 11, 2023 | Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted ... |
| CVE-2021-46768 | MEDIUM | 5.5 | 0.2% | Jan 11, 2023 | Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP... |
| CVE-2021-46767 | MEDIUM | 6.1 | 0.3% | Jan 11, 2023 | Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory... |
| CVE-2021-26407 | MEDIUM | 5.5 | 0.2% | Jan 11, 2023 | A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting i... |
| CVE-2021-26404 | MEDIUM | 5.5 | 0.2% | Jan 11, 2023 | Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential informa... |
| CVE-2021-26403 | MEDIUM | 6.5 | 0.1% | Jan 11, 2023 | Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in comp... |
| CVE-2021-26396 | MEDIUM | 4.4 | 0.1% | Jan 11, 2023 | Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity ... |
| CVE-2021-26355 | MEDIUM | 5.5 | 0.2% | Jan 11, 2023 | Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now