2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41458MEDIUM5.5In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vul...
CVE-2021-41415MEDIUM6.1Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.
CVE-2021-36891MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows chang...
CVE-2021-40776MEDIUM6.1Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom...
CVE-2021-41672MEDIUM6.5PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the adm...
CVE-2021-40910MEDIUM6.1There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.
CVE-2021-36901MEDIUM6.1Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Phil Baker's Age Gate plugin <= 2.17.0 at WordPress.
CVE-2021-40678MEDIUM5.4In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=bat...
CVE-2021-40658MEDIUM4.8Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
CVE-2021-40650MEDIUM6.5In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
CVE-2021-40649MEDIUM6.5In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
CVE-2021-40616MEDIUM6.5thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account wit...
CVE-2021-35121MEDIUM6.7An array index is improperly used to lock and unlock a mutex which can lead to a Use After Free condition In the Synx dr...
CVE-2021-35120MEDIUM6.7Improper handling between export and release functions on the same handle from client can lead to use after free in Snap...
CVE-2021-35119MEDIUM5.5Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snap...
CVE-2021-35118MEDIUM6.7An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Com...
CVE-2021-35111MEDIUM5.9Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivi...
CVE-2021-35101MEDIUM6.5Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, ...
CVE-2021-35098MEDIUM6.7Improper validation of session id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Co...
CVE-2021-35092MEDIUM6.7Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification...
CVE-2021-35080MEDIUM5.5Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon In...
CVE-2021-35079MEDIUM5.5Improper validation of permissions for third party application accessing Telephony service API can lead to information d...
CVE-2021-35071MEDIUM5.5Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to...
CVE-2021-35070MEDIUM5.5RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosu...
CVE-2021-30349MEDIUM6.7Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapd...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now