2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30276 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resourc... |
| CVE-2021-30275 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Sna... |
| CVE-2021-30274 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible integer overflow in access control initialization interface due to lack and size and address validation in Snap... |
| CVE-2021-30273 | HIGH | 7.5 | 0.6% | Jan 3, 2022 | Possible assertion due to improper handling of IPV6 packet with invalid length in destination options header in Snapdrag... |
| CVE-2021-30272 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in ... |
| CVE-2021-30271 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdra... |
| CVE-2021-30270 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencin... |
| CVE-2021-30269 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon... |
| CVE-2021-30268 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon... |
| CVE-2021-30267 | HIGH | 7.8 | 0.1% | Jan 3, 2022 | Possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands in Snapdragon Auto, Sn... |
| CVE-2021-30262 | HIGH | 7.8 | 0.1% | Jan 3, 2022 | Improper validation of a socket state when socket events are being sent to clients can lead to invalid access of memory ... |
| CVE-2021-1918 | MEDIUM | 6.5 | 0.1% | Jan 3, 2022 | Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT... |
| CVE-2021-1894 | HIGH | 7.8 | 0.2% | Jan 3, 2022 | Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, S... |
| CVE-2021-25994 | HIGH | 8.8 | 1.6% | Jan 3, 2022 | In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user ... |
| CVE-2021-25981 | CRITICAL | 9.8 | 2.5% | Jan 3, 2022 | In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerab... |
| CVE-2021-36751 | MEDIUM | 4.2 | 0.5% | Jan 2, 2022 | ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (w... |
| CVE-2021-44896 | MEDIUM | 6.1 | 0.9% | Jan 1, 2022 | DMP Roadmap before 3.0.4 allows XSS. |
| CVE-2021-45972 | HIGH | 7.1 | 1.0% | Jan 1, 2022 | The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file de... |
| CVE-2021-45960 | HIGH | 8.8 | 4.2% | Jan 1, 2022 | In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can le... |
| CVE-2021-44852 | HIGH | 7.8 | 0.8% | Jan 1, 2022 | An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the dr... |
| CVE-2021-43333 | MEDIUM | 6.5 | 0.7% | Jan 1, 2022 | The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or... |
| CVE-2021-41819 | HIGH | 7.5 | 2.9% | Jan 1, 2022 | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem thro... |
| CVE-2021-44717 | MEDIUM | 4.8 | 1.9% | Jan 1, 2022 | Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network c... |
| CVE-2021-44716 | HIGH | 7.5 | 4.0% | Jan 1, 2022 | net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicaliza... |
| CVE-2021-41817 | HIGH | 7.5 | 3.2% | Jan 1, 2022 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now