2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46758 | MEDIUM | 6.1 | 0.3% | Nov 14, 2023 | Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to rea... |
| CVE-2021-46748 | MEDIUM | 5.5 | 0.2% | Nov 14, 2023 | Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds... |
| CVE-2021-26345 | MEDIUM | 4.9 | 0.4% | Nov 14, 2023 | Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-b... |
| CVE-2021-43609 | HIGH | 8.8 | 2.0% | Nov 9, 2023 | An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within ... |
| CVE-2021-43419 | HIGH | 7.5 | 0.7% | Nov 7, 2023 | An Information Disclosure vulnerability exists in Opay Mobile application 1.5.1.26 and maybe be higher in the logcat app... |
| CVE-2021-4431 | MEDIUM | 6.1 | 0.6% | Nov 7, 2023 | A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of ... |
| CVE-2021-4430 | HIGH | 7.5 | 0.6% | Nov 6, 2023 | A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknow... |
| CVE-2021-39810 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactl... |
| CVE-2021-25736 | MEDIUM | 6.3 | 0.9% | Oct 30, 2023 | Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*... |
| CVE-2021-33638 | MEDIUM | 6.5 | 0.2% | Oct 29, 2023 | When the isula cp command is used to copy files from a container to a host machine and the container is controlled by a... |
| CVE-2021-33637 | MEDIUM | 6.5 | 0.2% | Oct 29, 2023 | When the isula export command is used to export a container to an image and the container is controlled by an attacker,... |
| CVE-2021-33636 | HIGH | 7.8 | 0.2% | Oct 29, 2023 | When the isula load command is used to load malicious images, attackers can execute arbitrary code. |
| CVE-2021-33635 | HIGH | 7.8 | 0.6% | Oct 29, 2023 | When malicious images are pulled by isula pull, attackers can execute arbitrary code. |
| CVE-2021-33634 | MEDIUM | 5.5 | 0.2% | Oct 29, 2023 | iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS. |
| CVE-2021-26738 | HIGH | 7.8 | 0.2% | Oct 23, 2023 | Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local... |
| CVE-2021-26737 | MEDIUM | 4.7 | 0.1% | Oct 23, 2023 | The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without... |
| CVE-2021-26736 | HIGH | 7.8 | 0.2% | Oct 23, 2023 | Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed exec... |
| CVE-2021-26735 | HIGH | 7.8 | 0.1% | Oct 23, 2023 | The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerabili... |
| CVE-2021-26734 | MEDIUM | 5.5 | 0.1% | Oct 23, 2023 | Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uni... |
| CVE-2021-46898 | MEDIUM | 6.1 | 0.5% | Oct 22, 2023 | views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with s... |
| CVE-2021-46897 | MEDIUM | 6.5 | 0.7% | Oct 22, 2023 | views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..... |
| CVE-2021-4418 | MEDIUM | 4.3 | 0.4% | Oct 20, 2023 | The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi... |
| CVE-2021-4334 | HIGH | 8.8 | 0.7% | Oct 20, 2023 | The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a miss... |
| CVE-2021-4353 | MEDIUM | 5.3 | 0.6% | Oct 20, 2023 | The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in v... |
| CVE-2021-4335 | MEDIUM | 6.3 | 0.4% | Oct 20, 2023 | The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now