2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46758MEDIUM6.1Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to rea...
CVE-2021-46748MEDIUM5.5Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds...
CVE-2021-26345MEDIUM4.9Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-b...
CVE-2021-43609HIGH8.8An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within ...
CVE-2021-43419HIGH7.5An Information Disclosure vulnerability exists in Opay Mobile application 1.5.1.26 and maybe be higher in the logcat app...
CVE-2021-4431MEDIUM6.1A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of ...
CVE-2021-4430HIGH7.5A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknow...
CVE-2021-39810HIGH7.8In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactl...
CVE-2021-25736MEDIUM6.3Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*...
CVE-2021-33638MEDIUM6.5 When the isula cp command is used to copy files from a container to a host machine and the container is controlled by a...
CVE-2021-33637MEDIUM6.5 When the isula export command is used to export a container to an image and the container is controlled by an attacker,...
CVE-2021-33636HIGH7.8 When the isula load command is used to load malicious images, attackers can execute arbitrary code.
CVE-2021-33635HIGH7.8When malicious images are pulled by isula pull, attackers can execute arbitrary code.
CVE-2021-33634MEDIUM5.5iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.
CVE-2021-26738HIGH7.8Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local...
CVE-2021-26737MEDIUM4.7The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without...
CVE-2021-26736HIGH7.8Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed exec...
CVE-2021-26735HIGH7.8The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerabili...
CVE-2021-26734MEDIUM5.5Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uni...
CVE-2021-46898MEDIUM6.1views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with s...
CVE-2021-46897MEDIUM6.5views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/.....
CVE-2021-4418MEDIUM4.3The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2021-4334HIGH8.8The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a miss...
CVE-2021-4353MEDIUM5.3The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in v...
CVE-2021-4335MEDIUM6.3The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now