2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24973 | MEDIUM | 6.1 | 1.3% | Jan 3, 2022 | The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_acti... |
| CVE-2021-24964 | MEDIUM | 6.1 | 1.2% | Jan 3, 2022 | The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud serv... |
| CVE-2021-24963 | MEDIUM | 4.8 | 0.7% | Jan 3, 2022 | The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the ... |
| CVE-2021-24893 | HIGH | 7.5 | 1.6% | Jan 3, 2022 | The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integ... |
| CVE-2021-24831 | HIGH | 7.5 | 1.2% | Jan 3, 2022 | All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users,... |
| CVE-2021-24828 | MEDIUM | 5.4 | 0.6% | Jan 3, 2022 | The Mortgage Calculator / Loan Calculator WordPress plugin before 1.5.17 does not escape the some of the attributes of i... |
| CVE-2021-24786 | HIGH | 7.2 | 17.5% | Jan 3, 2022 | The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter bef... |
| CVE-2021-24680 | MEDIUM | 5.4 | 0.6% | Jan 3, 2022 | The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activit... |
| CVE-2021-45917 | CRITICAL | 9 | 0.5% | Jan 3, 2022 | The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated ... |
| CVE-2021-45916 | LOW | 3.5 | 0.3% | Jan 3, 2022 | The programming function of Shockwall system has an improper input validation vulnerability. An authenticated attacker w... |
| CVE-2021-44158 | HIGH | 8 | 0.7% | Jan 3, 2022 | ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter l... |
| CVE-2021-35093 | MEDIUM | 6.5 | 0.2% | Jan 3, 2022 | Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial... |
| CVE-2021-30351 | CRITICAL | 9.8 | 4.0% | Jan 3, 2022 | An out of bound memory access can occur due to improper validation of number of frames being passed during music playbac... |
| CVE-2021-30348 | MEDIUM | 6.5 | 0.2% | Jan 3, 2022 | Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Comp... |
| CVE-2021-30337 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in... |
| CVE-2021-30336 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible out of bound read due to lack of domain input validation while processing APK close session request in Snapdrag... |
| CVE-2021-30335 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneo... |
| CVE-2021-30303 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, S... |
| CVE-2021-30298 | HIGH | 7.8 | 0.1% | Jan 3, 2022 | Possible out of bound access due to improper validation of item size and DIAG memory pools data while switching between ... |
| CVE-2021-30293 | HIGH | 7.5 | 0.6% | Jan 3, 2022 | Possible assertion due to lack of input validation in PUSCH configuration in Snapdragon Auto, Snapdragon Compute, Snapdr... |
| CVE-2021-30289 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Au... |
| CVE-2021-30283 | MEDIUM | 5.5 | 0.1% | Jan 3, 2022 | Possible denial of service due to improper handling of debug register trap from user applications in Snapdragon Consumer... |
| CVE-2021-30282 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdr... |
| CVE-2021-30279 | HIGH | 7.8 | 0.1% | Jan 3, 2022 | Possible access control violation while setting current permission for VMIDs due to improper permission masking in Snapd... |
| CVE-2021-30278 | MEDIUM | 5.5 | 0.1% | Jan 3, 2022 | Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now