2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35105 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon ... |
| CVE-2021-35103 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Possible out of bound write due to improper validation of number of timer values received from firmware while syncing ti... |
| CVE-2021-35089 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Possible buffer overflow due to lack of input IB amount validation while processing the user command in Snapdragon Auto |
| CVE-2021-35088 | CRITICAL | 9.1 | 0.8% | Apr 1, 2022 | Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdrago... |
| CVE-2021-30333 | HIGH | 7.8 | 0.1% | Apr 1, 2022 | Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Co... |
| CVE-2021-30332 | HIGH | 7.5 | 0.5% | Apr 1, 2022 | Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Co... |
| CVE-2021-30331 | MEDIUM | 5.5 | 0.1% | Apr 1, 2022 | Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto... |
| CVE-2021-30329 | HIGH | 7.5 | 0.6% | Apr 1, 2022 | Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Co... |
| CVE-2021-30328 | HIGH | 7.5 | 0.6% | Apr 1, 2022 | Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon... |
| CVE-2021-1950 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto... |
| CVE-2021-1942 | HIGH | 8.8 | 0.1% | Apr 1, 2022 | Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon ... |
| CVE-2021-46439 | — | — | — | Mar 31, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-43722 | CRITICAL | 9.8 | 3.1% | Mar 31, 2022 | D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to fo... |
| CVE-2021-43707 | MEDIUM | 6.1 | 0.6% | Mar 31, 2022 | Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. |
| CVE-2021-43479 | CRITICAL | 9.8 | 2.4% | Mar 31, 2022 | A Remote Code Execution (RCE) vulnerability exists in The-Secretary 2.5 via install.php. |
| CVE-2021-43484 | CRITICAL | 9.8 | 3.3% | Mar 31, 2022 | A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failu... |
| CVE-2021-43478 | MEDIUM | 5.4 | 0.8% | Mar 31, 2022 | A vulnerability exists in Hoosk 1.8.0 in /install/index.php, due to a failure to check if config.php already exists in t... |
| CVE-2021-37517 | HIGH | 7.5 | 0.9% | Mar 31, 2022 | An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password functi... |
| CVE-2021-42946 | MEDIUM | 4.8 | 0.5% | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page. |
| CVE-2021-42869 | MEDIUM | 4.8 | 0.5% | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parame... |
| CVE-2021-42868 | MEDIUM | 4.8 | 0.8% | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parame... |
| CVE-2021-42867 | MEDIUM | 4.8 | 0.6% | Mar 31, 2022 | A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, ... |
| CVE-2021-42866 | MEDIUM | 4.8 | 0.5% | Mar 31, 2022 | A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.... |
| CVE-2021-36625 | HIGH | 8.8 | 0.9% | Mar 31, 2022 | An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the cou... |
| CVE-2021-43506 | CRITICAL | 9.8 | 1.6% | Mar 31, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter i... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now