2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-41841HIGH8.2An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that al...
CVE-2021-41840HIGH8.2An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that...
CVE-2021-41839HIGH8.2An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Poin...
CVE-2021-41838HIGH8.2An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that ...
CVE-2021-41837HIGH8.2An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer...
CVE-2021-33627HIGH8.2An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 be...
CVE-2021-33625HIGH7.5An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Com...
CVE-2021-43522HIGH7.5An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through ...
CVE-2021-42642HIGH7.5PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul...
CVE-2021-42641HIGH7.5PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul...
CVE-2021-41018HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio...
CVE-2021-39066HIGH8.8IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker th...
CVE-2021-39044HIGH8.8IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2021-36193HIGH7.2Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticate...
CVE-2021-43073HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio...
CVE-2021-42753HIGH8.1An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb man...
CVE-2021-41016HIGH8.8A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version ...
CVE-2021-42638HIGH8.1PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code exe...
CVE-2021-25093HIGH7.5The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauth...
CVE-2021-24919HIGH8.8The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it i...
CVE-2021-24763HIGH8.8The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_s...
CVE-2021-43859HIGH7.5XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a ...
CVE-2021-41040HIGH7.5In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-...
CVE-2021-46669HIGH7.5MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is us...
CVE-2021-46459HIGH7.5Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now