2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26379 | CRITICAL | 9.8 | 0.7% | May 9, 2023 | Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, poten... |
| CVE-2021-26371 | MEDIUM | 5.5 | 0.2% | May 9, 2023 | A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure o... |
| CVE-2021-26365 | HIGH | 8.2 | 0.6% | May 9, 2023 | Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to... |
| CVE-2021-26356 | HIGH | 7.4 | 0.4% | May 9, 2023 | A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially re... |
| CVE-2021-26354 | MEDIUM | 5.5 | 0.2% | May 9, 2023 | Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause ... |
| CVE-2021-31711 | MEDIUM | 5.4 | 0.5% | May 9, 2023 | Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to... |
| CVE-2021-31240 | HIGH | 7.8 | 0.3% | May 9, 2023 | An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS functi... |
| CVE-2021-44283 | HIGH | 7.5 | 0.9% | May 9, 2023 | A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore com... |
| CVE-2021-31239 | HIGH | 7.5 | 2.2% | May 9, 2023 | An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c... |
| CVE-2021-28999 | HIGH | 8.8 | 1.3% | May 8, 2023 | SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via ... |
| CVE-2021-28998 | HIGH | 7.2 | 1.3% | May 8, 2023 | File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via... |
| CVE-2021-27280 | HIGH | 7.8 | 1.0% | May 8, 2023 | OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it g... |
| CVE-2021-40331 | HIGH | 8.1 | 0.9% | May 5, 2023 | An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any u... |
| CVE-2021-45111 | HIGH | 8.1 | 0.8% | Apr 25, 2023 | Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authentica... |
| CVE-2021-45071 | MEDIUM | 6.1 | 0.7% | Apr 25, 2023 | Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att... |
| CVE-2021-44775 | MEDIUM | 6.1 | 0.5% | Apr 25, 2023 | Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier,... |
| CVE-2021-44547 | CRITICAL | 9.1 | 0.7% | Apr 25, 2023 | A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbit... |
| CVE-2021-44476 | MEDIUM | 6.8 | 0.5% | Apr 25, 2023 | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administ... |
| CVE-2021-44465 | MEDIUM | 4.3 | 0.5% | Apr 25, 2023 | Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated att... |
| CVE-2021-44461 | MEDIUM | 6.1 | 0.5% | Apr 25, 2023 | Cross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are... |
| CVE-2021-44460 | MEDIUM | 6.5 | 0.7% | Apr 25, 2023 | Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deacti... |
| CVE-2021-26947 | MEDIUM | 6.1 | 1.4% | Apr 25, 2023 | Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att... |
| CVE-2021-26263 | MEDIUM | 6.1 | 0.6% | Apr 25, 2023 | Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15... |
| CVE-2021-23203 | HIGH | 7.5 | 0.9% | Apr 25, 2023 | Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, ... |
| CVE-2021-23186 | HIGH | 8.7 | 0.6% | Apr 25, 2023 | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now