2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26399Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-26385Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-26374Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-26358Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-26357Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-26319Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-4313CRITICAL9.8A vulnerability was found in NethServer phonenehome. It has been rated as critical. This issue affects the function get_...
CVE-2021-36204HIGH7.5Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 1...
CVE-2021-4312MEDIUM6.1** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in Th3-822 Rapidleech. This aff...
CVE-2021-46872MEDIUM6.1An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other pr...
CVE-2021-46795MEDIUM4.7A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the T...
CVE-2021-46791MEDIUM5.5Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted ...
CVE-2021-46779HIGH7.1Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an att...
CVE-2021-46768MEDIUM5.5Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP...
CVE-2021-46767MEDIUM6.1Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory...
CVE-2021-26409HIGH7.8Insufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resu...
CVE-2021-26407MEDIUM5.5A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting i...
CVE-2021-26404MEDIUM5.5Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential informa...
CVE-2021-26403MEDIUM6.5Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in comp...
CVE-2021-26402HIGH7.1Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an a...
CVE-2021-26398HIGH7.8Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attack...
CVE-2021-26396MEDIUM4.4Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity ...
CVE-2021-26355MEDIUM5.5Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers t...
CVE-2021-26346MEDIUM5.5Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an i...
CVE-2021-26343MEDIUM5.5Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the conten...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now