2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-30276HIGH7.8Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resourc...
CVE-2021-30275HIGH7.8Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Sna...
CVE-2021-30274HIGH7.8Possible integer overflow in access control initialization interface due to lack and size and address validation in Snap...
CVE-2021-30273HIGH7.5Possible assertion due to improper handling of IPV6 packet with invalid length in destination options header in Snapdrag...
CVE-2021-30272HIGH7.8Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in ...
CVE-2021-30271HIGH7.8Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdra...
CVE-2021-30270HIGH7.8Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencin...
CVE-2021-30269HIGH7.8Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon...
CVE-2021-30268HIGH7.8Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon...
CVE-2021-30267HIGH7.8Possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands in Snapdragon Auto, Sn...
CVE-2021-30262HIGH7.8Improper validation of a socket state when socket events are being sent to clients can lead to invalid access of memory ...
CVE-2021-1918MEDIUM6.5Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT...
CVE-2021-1894HIGH7.8Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, S...
CVE-2021-25994HIGH8.8In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user ...
CVE-2021-25981CRITICAL9.8In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerab...
CVE-2021-36751MEDIUM4.2ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (w...
CVE-2021-44896MEDIUM6.1DMP Roadmap before 3.0.4 allows XSS.
CVE-2021-45972HIGH7.1The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file de...
CVE-2021-45960HIGH8.8In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can le...
CVE-2021-44852HIGH7.8An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the dr...
CVE-2021-43333MEDIUM6.5The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or...
CVE-2021-41819HIGH7.5CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem thro...
CVE-2021-44717MEDIUM4.8Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network c...
CVE-2021-44716HIGH7.5net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicaliza...
CVE-2021-41817HIGH7.5Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now