2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46355 | MEDIUM | 5.4 | 1.1% | Feb 11, 2022 | OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manip... |
| CVE-2021-44521 | CRITICAL | 9.1 | 54.9% | Feb 11, 2022 | When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user... |
| CVE-2021-35077 | HIGH | 7.8 | 0.2% | Feb 11, 2022 | Possible use after free scenario in compute offloads to DSP while multiple calls spawn a dynamic process in Snapdragon A... |
| CVE-2021-35075 | HIGH | 7.8 | 0.2% | Feb 11, 2022 | Possible null pointer dereference due to lack of WDOG structure validation during registration in Snapdragon Auto, Snapd... |
| CVE-2021-35074 | HIGH | 7.8 | 0.2% | Feb 11, 2022 | Possible integer overflow due to improper fragment datatype while calculating number of fragments in a request message i... |
| CVE-2021-35069 | HIGH | 7.8 | 0.2% | Feb 11, 2022 | Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdrago... |
| CVE-2021-35068 | CRITICAL | 9.8 | 0.5% | Feb 11, 2022 | Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer ... |
| CVE-2021-30326 | HIGH | 7.5 | 0.6% | Feb 11, 2022 | Possible assertion due to improper size validation while processing the DownlinkPreemption IE in an RRC Reconfiguration/... |
| CVE-2021-30325 | MEDIUM | 6.7 | 0.1% | Feb 11, 2022 | Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Au... |
| CVE-2021-30324 | MEDIUM | 6.7 | 0.1% | Feb 11, 2022 | Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to re... |
| CVE-2021-30323 | HIGH | 7.8 | 0.2% | Feb 11, 2022 | Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdrag... |
| CVE-2021-30322 | HIGH | 7.8 | 0.2% | Feb 11, 2022 | Possible out of bounds write due to improper validation of number of GPIOs configured in an internal parameters array in... |
| CVE-2021-30318 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | Improper validation of input when provisioning the HDCP key can lead to memory corruption in Snapdragon Auto, Snapdragon... |
| CVE-2021-30317 | HIGH | 7.8 | 1.4% | Feb 11, 2022 | Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto,... |
| CVE-2021-30309 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | Improper size validation of QXDM commands can lead to memory corruption in Snapdragon Compute, Snapdragon Consumer IOT, ... |
| CVE-2021-44970 | MEDIUM | 5.4 | 0.5% | Feb 10, 2022 | MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php. |
| CVE-2021-44969 | MEDIUM | 4.8 | 0.5% | Feb 10, 2022 | Taocms v3.0.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Management Column component. |
| CVE-2021-42000 | MEDIUM | 6.5 | 0.5% | Feb 10, 2022 | When a password reset or password change flow with an authentication policy is configured and the adapter in the reset o... |
| CVE-2021-45364 | CRITICAL | 9.8 | 1.6% | Feb 10, 2022 | A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor in... |
| CVE-2021-44850 | MEDIUM | 6.8 | 0.2% | Feb 10, 2022 | On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the RO... |
| CVE-2021-45357 | MEDIUM | 6.1 | 0.8% | Feb 10, 2022 | Cross Site Scripting (XSS) vulnerability exists in Piwigo 12.x via the pwg_activity function in include/functions.inc.ph... |
| CVE-2021-44892 | HIGH | 8.8 | 1.9% | Feb 10, 2022 | A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let ... |
| CVE-2021-41445 | MEDIUM | 6.1 | 2.4% | Feb 10, 2022 | A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote un... |
| CVE-2021-3398 | MEDIUM | 5.8 | 0.9% | Feb 10, 2022 | Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component. |
| CVE-2021-37613 | MEDIUM | 6.5 | 0.4% | Feb 10, 2022 | Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now