2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-25000MEDIUM6.1The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter bef...
CVE-2021-24999MEDIUM6.1The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before o...
CVE-2021-24991MEDIUM4.8The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section paramete...
CVE-2021-24973MEDIUM6.1The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_acti...
CVE-2021-24964MEDIUM6.1The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud serv...
CVE-2021-24963MEDIUM4.8The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the ...
CVE-2021-24828MEDIUM5.4The Mortgage Calculator / Loan Calculator WordPress plugin before 1.5.17 does not escape the some of the attributes of i...
CVE-2021-24680MEDIUM5.4The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activit...
CVE-2021-35093MEDIUM6.5Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial...
CVE-2021-30348MEDIUM6.5Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Comp...
CVE-2021-30283MEDIUM5.5Possible denial of service due to improper handling of debug register trap from user applications in Snapdragon Consumer...
CVE-2021-30278MEDIUM5.5Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, ...
CVE-2021-1918MEDIUM6.5Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT...
CVE-2021-36751MEDIUM4.2ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (w...
CVE-2021-44896MEDIUM6.1DMP Roadmap before 3.0.4 allows XSS.
CVE-2021-43333MEDIUM6.5The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or...
CVE-2021-44717MEDIUM4.8Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network c...
CVE-2021-45943MEDIUM5.5GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCI...
CVE-2021-45942MEDIUM5.5OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThrea...
CVE-2021-45941MEDIUM6.5libbpf 0.6.0 and 0.6.1 has a heap-based buffer overflow (8 bytes) in __bpf_object__open (called from bpf_object__open_me...
CVE-2021-45940MEDIUM6.5libbpf 0.6.0 and 0.6.1 has a heap-based buffer overflow (4 bytes) in __bpf_object__open (called from bpf_object__open_me...
CVE-2021-45939MEDIUM5.5wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and Mq...
CVE-2021-45938MEDIUM5.5wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and Mq...
CVE-2021-45937MEDIUM5.5wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and Mq...
CVE-2021-45936MEDIUM5.5wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttDecode_Disconnect (called from MqttClient_DecodePacket and ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now