2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33074 | MEDIUM | 4.6 | 0.3% | May 12, 2022 | Protection mechanism failure in firmware for some Intel(R) SSD, Intel(R) SSD DC and Intel(R) Optane(TM) SSD Products may... |
| CVE-2021-33069 | MEDIUM | 5.5 | 0.2% | May 12, 2022 | Improper resource shutdown or release in firmware for some Intel(R) SSD, Intel(R) SSD DC, Intel(R) Optane(TM) SSD and In... |
| CVE-2021-0155 | MEDIUM | 5.5 | 0.3% | May 12, 2022 | Unchecked return value in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enab... |
| CVE-2021-42648 | MEDIUM | 6.1 | 0.8% | May 11, 2022 | Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrar... |
| CVE-2021-36614 | MEDIUM | 6.5 | 2.1% | May 11, 2022 | Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An au... |
| CVE-2021-36613 | MEDIUM | 6.5 | 2.1% | May 11, 2022 | Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticat... |
| CVE-2021-31330 | MEDIUM | 5.4 | 0.8% | May 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authen... |
| CVE-2021-28290 | MEDIUM | 6.1 | 0.6% | May 11, 2022 | A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to t... |
| CVE-2021-46744 | MEDIUM | 6.5 | 0.3% | May 11, 2022 | An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by mo... |
| CVE-2021-30361 | MEDIUM | 6.7 | 4.1% | May 11, 2022 | The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients setti... |
| CVE-2021-26400 | MEDIUM | 4 | 0.2% | May 11, 2022 | AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple ... |
| CVE-2021-26388 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposin... |
| CVE-2021-26378 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that coul... |
| CVE-2021-26376 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resultin... |
| CVE-2021-26375 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to... |
| CVE-2021-26373 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could resu... |
| CVE-2021-26372 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address... |
| CVE-2021-26364 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM ... |
| CVE-2021-26350 | MEDIUM | 4.7 | 0.1% | May 11, 2022 | A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register ... |
| CVE-2021-26349 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into ... |
| CVE-2021-26348 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device ... |
| CVE-2021-26347 | MEDIUM | 4.7 | 0.2% | May 11, 2022 | Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an i... |
| CVE-2021-26339 | MEDIUM | 5.5 | 0.3% | May 11, 2022 | A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU c... |
| CVE-2021-3611 | MEDIUM | 6.5 | 0.5% | May 11, 2022 | A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use t... |
| CVE-2021-39059 | MEDIUM | 5.4 | 0.4% | May 11, 2022 | IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now