2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30269 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon... |
| CVE-2021-30268 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon... |
| CVE-2021-30267 | HIGH | 7.8 | 0.1% | Jan 3, 2022 | Possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands in Snapdragon Auto, Sn... |
| CVE-2021-30262 | HIGH | 7.8 | 0.1% | Jan 3, 2022 | Improper validation of a socket state when socket events are being sent to clients can lead to invalid access of memory ... |
| CVE-2021-1894 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, S... |
| CVE-2021-25994 | HIGH | 8.8 | 1.6% | Jan 3, 2022 | In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user ... |
| CVE-2021-45972 | HIGH | 7.1 | 1.0% | Jan 1, 2022 | The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file de... |
| CVE-2021-45960 | HIGH | 8.8 | 4.2% | Jan 1, 2022 | In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can le... |
| CVE-2021-44852 | HIGH | 7.8 | 0.8% | Jan 1, 2022 | An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the dr... |
| CVE-2021-41819 | HIGH | 7.5 | 2.9% | Jan 1, 2022 | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem thro... |
| CVE-2021-44716 | HIGH | 7.5 | 4.0% | Jan 1, 2022 | net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicaliza... |
| CVE-2021-41817 | HIGH | 7.5 | 3.2% | Jan 1, 2022 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string.... |
| CVE-2021-45927 | HIGH | 7.8 | 0.4% | Jan 1, 2022 | MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd6e029ee0) in mdb_numeric_to_string (called fr... |
| CVE-2021-45926 | HIGH | 7.8 | 0.4% | Jan 1, 2022 | MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd0c689be0) in mdb_numeric_to_string (called fr... |
| CVE-2021-4192 | HIGH | 7.8 | 1.7% | Dec 31, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-4190 | HIGH | 7.5 | 3.1% | Dec 30, 2021 | Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture fi... |
| CVE-2021-4186 | HIGH | 7.5 | 2.2% | Dec 30, 2021 | Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted cap... |
| CVE-2021-4185 | HIGH | 7.5 | 3.9% | Dec 30, 2021 | Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injectio... |
| CVE-2021-4184 | HIGH | 7.5 | 3.9% | Dec 30, 2021 | Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet... |
| CVE-2021-4182 | HIGH | 7.5 | 3.3% | Dec 30, 2021 | Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or ... |
| CVE-2021-4181 | HIGH | 7.5 | 3.8% | Dec 30, 2021 | Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection... |
| CVE-2021-45732 | HIGH | 8.8 | 0.8% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are ... |
| CVE-2021-45077 | HIGH | 7.5 | 0.6% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the... |
| CVE-2021-44466 | HIGH | 7.3 | 0.4% | Dec 30, 2021 | Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software ... |
| CVE-2021-20175 | HIGH | 7.5 | 0.6% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By defaul... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now