2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41841 | HIGH | 8.2 | 0.3% | Feb 3, 2022 | An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that al... |
| CVE-2021-41840 | HIGH | 8.2 | 0.3% | Feb 3, 2022 | An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that... |
| CVE-2021-41839 | HIGH | 8.2 | 0.3% | Feb 3, 2022 | An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Poin... |
| CVE-2021-41838 | HIGH | 8.2 | 0.3% | Feb 3, 2022 | An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that ... |
| CVE-2021-41837 | HIGH | 8.2 | 0.3% | Feb 3, 2022 | An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer... |
| CVE-2021-33627 | HIGH | 8.2 | 0.3% | Feb 3, 2022 | An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 be... |
| CVE-2021-33625 | HIGH | 7.5 | 0.3% | Feb 3, 2022 | An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Com... |
| CVE-2021-43522 | HIGH | 7.5 | 0.3% | Feb 3, 2022 | An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through ... |
| CVE-2021-42642 | HIGH | 7.5 | 1.4% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul... |
| CVE-2021-42641 | HIGH | 7.5 | 2.1% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul... |
| CVE-2021-41018 | HIGH | 8.8 | 3.3% | Feb 2, 2022 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio... |
| CVE-2021-39066 | HIGH | 8.8 | 0.6% | Feb 2, 2022 | IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker th... |
| CVE-2021-39044 | HIGH | 8.8 | 0.4% | Feb 2, 2022 | IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to exe... |
| CVE-2021-36193 | HIGH | 7.2 | 0.8% | Feb 2, 2022 | Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticate... |
| CVE-2021-43073 | HIGH | 8.8 | 1.4% | Feb 2, 2022 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio... |
| CVE-2021-42753 | HIGH | 8.1 | 1.1% | Feb 2, 2022 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb man... |
| CVE-2021-41016 | HIGH | 8.8 | 1.1% | Feb 2, 2022 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version ... |
| CVE-2021-42638 | HIGH | 8.1 | 5.7% | Feb 1, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code exe... |
| CVE-2021-25093 | HIGH | 7.5 | 1.2% | Feb 1, 2022 | The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauth... |
| CVE-2021-24919 | HIGH | 8.8 | 1.5% | Feb 1, 2022 | The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it i... |
| CVE-2021-24763 | HIGH | 8.8 | 0.6% | Feb 1, 2022 | The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_s... |
| CVE-2021-43859 | HIGH | 7.5 | 8.2% | Feb 1, 2022 | XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a ... |
| CVE-2021-41040 | HIGH | 7.5 | 1.4% | Feb 1, 2022 | In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-... |
| CVE-2021-46669 | HIGH | 7.5 | 2.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is us... |
| CVE-2021-46459 | HIGH | 7.5 | 1.4% | Jan 31, 2022 | Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now