2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-35105HIGH7.8Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon ...
CVE-2021-35103HIGH7.8Possible out of bound write due to improper validation of number of timer values received from firmware while syncing ti...
CVE-2021-35089HIGH7.8Possible buffer overflow due to lack of input IB amount validation while processing the user command in Snapdragon Auto
CVE-2021-35088CRITICAL9.1Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdrago...
CVE-2021-30333HIGH7.8Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Co...
CVE-2021-30332HIGH7.5Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Co...
CVE-2021-30331MEDIUM5.5Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto...
CVE-2021-30329HIGH7.5Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Co...
CVE-2021-30328HIGH7.5Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon...
CVE-2021-1950HIGH7.8Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto...
CVE-2021-1942HIGH8.8Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon ...
CVE-2021-46439Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-43722CRITICAL9.8D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to fo...
CVE-2021-43707MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
CVE-2021-43479CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in The-Secretary 2.5 via install.php.
CVE-2021-43484CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failu...
CVE-2021-43478MEDIUM5.4A vulnerability exists in Hoosk 1.8.0 in /install/index.php, due to a failure to check if config.php already exists in t...
CVE-2021-37517HIGH7.5An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password functi...
CVE-2021-42946MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.
CVE-2021-42869MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parame...
CVE-2021-42868MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parame...
CVE-2021-42867MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, ...
CVE-2021-42866MEDIUM4.8A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting....
CVE-2021-36625HIGH8.8An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the cou...
CVE-2021-43506CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter i...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now