2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27131MEDIUM5.4Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on th...
CVE-2021-0877CRITICAL9.8Product: AndroidVersions: Android SoCAndroid ID: A-273754094
CVE-2021-26674Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-26673Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-39036MEDIUM6.1IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2021-34076HIGH8.8File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges v...
CVE-2021-45345HIGH7.5Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service...
CVE-2021-46794HIGH7.5Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management...
CVE-2021-46792MEDIUM5.9Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race ...
CVE-2021-46773HIGH8.8Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a ...
CVE-2021-46765HIGH7.5Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads w...
CVE-2021-46760CRITICAL9.8A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of...
CVE-2021-46759MEDIUM6.1Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access ...
CVE-2021-46756CRITICAL9.1Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attack...
CVE-2021-46755HIGH7.5Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attack...
CVE-2021-46754CRITICAL9.1Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp...
CVE-2021-46775MEDIUM6.8Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, po...
CVE-2021-46769HIGH8.8Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA cop...
CVE-2021-46764HIGH7.5Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the AS...
CVE-2021-46763HIGH7.5Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a share...
CVE-2021-46762CRITICAL9.1Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of inte...
CVE-2021-46753CRITICAL9.1Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker ...
CVE-2021-46749HIGH7.5Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management...
CVE-2021-26406HIGH7.5Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtual...
CVE-2021-26397HIGH7.1Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locat...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now