2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24973MEDIUM6.1The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_acti...
CVE-2021-24964MEDIUM6.1The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud serv...
CVE-2021-24963MEDIUM4.8The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the ...
CVE-2021-24893HIGH7.5The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integ...
CVE-2021-24831HIGH7.5All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users,...
CVE-2021-24828MEDIUM5.4The Mortgage Calculator / Loan Calculator WordPress plugin before 1.5.17 does not escape the some of the attributes of i...
CVE-2021-24786HIGH7.2The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter bef...
CVE-2021-24680MEDIUM5.4The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activit...
CVE-2021-45917CRITICAL9The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated ...
CVE-2021-45916LOW3.5The programming function of Shockwall system has an improper input validation vulnerability. An authenticated attacker w...
CVE-2021-44158HIGH8ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter l...
CVE-2021-35093MEDIUM6.5Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial...
CVE-2021-30351CRITICAL9.8An out of bound memory access can occur due to improper validation of number of frames being passed during music playbac...
CVE-2021-30348MEDIUM6.5Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Comp...
CVE-2021-30337HIGH7.8Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in...
CVE-2021-30336HIGH7.8Possible out of bound read due to lack of domain input validation while processing APK close session request in Snapdrag...
CVE-2021-30335HIGH7.8Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneo...
CVE-2021-30303HIGH7.8Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, S...
CVE-2021-30298HIGH7.8Possible out of bound access due to improper validation of item size and DIAG memory pools data while switching between ...
CVE-2021-30293HIGH7.5Possible assertion due to lack of input validation in PUSCH configuration in Snapdragon Auto, Snapdragon Compute, Snapdr...
CVE-2021-30289HIGH7.8Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Au...
CVE-2021-30283MEDIUM5.5Possible denial of service due to improper handling of debug register trap from user applications in Snapdragon Consumer...
CVE-2021-30282HIGH7.8Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdr...
CVE-2021-30279HIGH7.8Possible access control violation while setting current permission for VMIDs due to improper permission masking in Snapd...
CVE-2021-30278MEDIUM5.5Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now