2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35089 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Possible buffer overflow due to lack of input IB amount validation while processing the user command in Snapdragon Auto |
| CVE-2021-30333 | HIGH | 7.8 | 0.1% | Apr 1, 2022 | Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Co... |
| CVE-2021-30332 | HIGH | 7.5 | 0.5% | Apr 1, 2022 | Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Co... |
| CVE-2021-30329 | HIGH | 7.5 | 0.6% | Apr 1, 2022 | Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Co... |
| CVE-2021-30328 | HIGH | 7.5 | 0.6% | Apr 1, 2022 | Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon... |
| CVE-2021-1950 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto... |
| CVE-2021-1942 | HIGH | 8.8 | 0.1% | Apr 1, 2022 | Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon ... |
| CVE-2021-37517 | HIGH | 7.5 | 0.9% | Mar 31, 2022 | An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password functi... |
| CVE-2021-36625 | HIGH | 8.8 | 0.9% | Mar 31, 2022 | An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the cou... |
| CVE-2021-34257 | HIGH | 8.8 | 1.7% | Mar 31, 2022 | Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload t... |
| CVE-2021-43663 | HIGH | 7.5 | 1.0% | Mar 31, 2022 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cl... |
| CVE-2021-46010 | HIGH | 8.8 | 1.6% | Mar 30, 2022 | Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is... |
| CVE-2021-46008 | HIGH | 8.8 | 1.2% | Mar 30, 2022 | In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An atta... |
| CVE-2021-43664 | HIGH | 8.1 | 1.7% | Mar 30, 2022 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component pr... |
| CVE-2021-33523 | HIGH | 7.2 | 1.8% | Mar 30, 2022 | MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new J... |
| CVE-2021-33581 | HIGH | 7.2 | 1.2% | Mar 30, 2022 | MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP servic... |
| CVE-2021-33208 | HIGH | 7.2 | 1.1% | Mar 30, 2022 | The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a ... |
| CVE-2021-45031 | HIGH | 7.7 | 0.8% | Mar 30, 2022 | A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate hi... |
| CVE-2021-44312 | HIGH | 8.8 | 0.4% | Mar 30, 2022 | An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a C... |
| CVE-2021-3456 | HIGH | 7.1 | 0.2% | Mar 30, 2022 | An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients... |
| CVE-2021-39790 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could... |
| CVE-2021-39789 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local esca... |
| CVE-2021-39787 | HIGH | 7.8 | 0.4% | Mar 30, 2022 | In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation... |
| CVE-2021-39784 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission chec... |
| CVE-2021-39783 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local es... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now