2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26379CRITICAL9.8Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, poten...
CVE-2021-26371MEDIUM5.5A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure o...
CVE-2021-26365HIGH8.2Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to...
CVE-2021-26356HIGH7.4A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially re...
CVE-2021-26354MEDIUM5.5Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause ...
CVE-2021-31711MEDIUM5.4Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to...
CVE-2021-31240HIGH7.8An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS functi...
CVE-2021-44283HIGH7.5A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore com...
CVE-2021-31239HIGH7.5An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c...
CVE-2021-28999HIGH8.8SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via ...
CVE-2021-28998HIGH7.2File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via...
CVE-2021-27280HIGH7.8OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it g...
CVE-2021-40331HIGH8.1An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any u...
CVE-2021-45111HIGH8.1Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authentica...
CVE-2021-45071MEDIUM6.1Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att...
CVE-2021-44775MEDIUM6.1Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier,...
CVE-2021-44547CRITICAL9.1A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbit...
CVE-2021-44476MEDIUM6.8A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administ...
CVE-2021-44465MEDIUM4.3Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated att...
CVE-2021-44461MEDIUM6.1Cross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are...
CVE-2021-44460MEDIUM6.5Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deacti...
CVE-2021-26947MEDIUM6.1Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att...
CVE-2021-26263MEDIUM6.1Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15...
CVE-2021-23203HIGH7.5Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, ...
CVE-2021-23186HIGH8.7A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now