2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1915 | HIGH | 7.8 | 0.2% | May 7, 2021 | Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdrago... |
| CVE-2021-1910 | CRITICAL | 9.8 | 0.6% | May 7, 2021 | Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect... |
| CVE-2021-1906 | MEDIUM | 5.5 | 0.5% | May 7, 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Aut... |
| CVE-2021-1905 | HIGH | 7.8 | 1.1% | May 7, 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon A... |
| CVE-2021-1895 | HIGH | 7.8 | 0.2% | May 7, 2021 | Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon In... |
| CVE-2021-1891 | HIGH | 7.8 | 0.1% | May 7, 2021 | A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Aut... |
| CVE-2021-32093 | MEDIUM | 6.5 | 1.0% | May 7, 2021 | The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to rea... |
| CVE-2021-32092 | MEDIUM | 6.1 | 1.0% | May 7, 2021 | A Cross-site scripting (XSS) vulnerability in the DocumentAction component of U.S. National Security Agency (NSA) Emissa... |
| CVE-2021-32091 | MEDIUM | 6.1 | 0.8% | May 7, 2021 | A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6. |
| CVE-2021-32090 | CRITICAL | 9.8 | 2.1% | May 7, 2021 | The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the funct... |
| CVE-2021-32074 | HIGH | 7.5 | 1.9% | May 7, 2021 | HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log ... |
| CVE-2021-32104 | HIGH | 8.8 | 1.2% | May 7, 2021 | A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1. |
| CVE-2021-32103 | MEDIUM | 4.8 | 0.7% | May 7, 2021 | A Stored XSS vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.1 allows a admin authentic... |
| CVE-2021-32102 | HIGH | 8.8 | 1.2% | May 7, 2021 | A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1. |
| CVE-2021-32101 | HIGH | 8.2 | 1.2% | May 7, 2021 | The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config... |
| CVE-2021-32100 | MEDIUM | 6.5 | 2.6% | May 7, 2021 | A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user. |
| CVE-2021-32099 | CRITICAL | 9.8 | 11.4% | May 7, 2021 | A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attac... |
| CVE-2021-32098 | CRITICAL | 9.8 | 2.5% | May 7, 2021 | Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization. |
| CVE-2021-32096 | HIGH | 8.8 | 0.6% | May 7, 2021 | The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in i... |
| CVE-2021-32095 | HIGH | 8.1 | 0.9% | May 7, 2021 | U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files. |
| CVE-2021-32094 | HIGH | 8.8 | 1.2% | May 7, 2021 | U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files. |
| CVE-2021-32077 | HIGH | 7.5 | 1.2% | May 6, 2021 | Primary Source Verification in VerityStream MSOW Solutions before 3.1.1 allows an anonymous internet user to discover So... |
| CVE-2021-31737 | CRITICAL | 9.8 | 3.9% | May 6, 2021 | emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/... |
| CVE-2021-29203 | CRITICAL | 9.8 | 68.3% | May 6, 2021 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr... |
| CVE-2021-27941 | MEDIUM | 4.6 | 0.2% | May 6, 2021 | Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile applic... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now