2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-35089HIGH7.8Possible buffer overflow due to lack of input IB amount validation while processing the user command in Snapdragon Auto
CVE-2021-30333HIGH7.8Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Co...
CVE-2021-30332HIGH7.5Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Co...
CVE-2021-30329HIGH7.5Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Co...
CVE-2021-30328HIGH7.5Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon...
CVE-2021-1950HIGH7.8Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto...
CVE-2021-1942HIGH8.8Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon ...
CVE-2021-37517HIGH7.5An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password functi...
CVE-2021-36625HIGH8.8An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the cou...
CVE-2021-34257HIGH8.8Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload t...
CVE-2021-43663HIGH7.5totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cl...
CVE-2021-46010HIGH8.8Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is...
CVE-2021-46008HIGH8.8In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An atta...
CVE-2021-43664HIGH8.1totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component pr...
CVE-2021-33523HIGH7.2MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new J...
CVE-2021-33581HIGH7.2MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP servic...
CVE-2021-33208HIGH7.2The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a ...
CVE-2021-45031HIGH7.7A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate hi...
CVE-2021-44312HIGH8.8An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a C...
CVE-2021-3456HIGH7.1An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients...
CVE-2021-39790HIGH7.8In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could...
CVE-2021-39789HIGH7.8In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local esca...
CVE-2021-39787HIGH7.8In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation...
CVE-2021-39784HIGH7.8In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission chec...
CVE-2021-39783HIGH7.8In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local es...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now