2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39664 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This cou... |
| CVE-2021-39631 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wron... |
| CVE-2021-0524 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages ... |
| CVE-2021-45387 | MEDIUM | 5.5 | 0.7% | Feb 11, 2022 | tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c. |
| CVE-2021-45386 | MEDIUM | 5.5 | 0.7% | Feb 11, 2022 | tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c |
| CVE-2021-45385 | MEDIUM | 6.5 | 0.9% | Feb 11, 2022 | A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information i... |
| CVE-2021-45402 | MEDIUM | 5.5 | 0.4% | Feb 11, 2022 | The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bound... |
| CVE-2021-46355 | MEDIUM | 5.4 | 1.1% | Feb 11, 2022 | OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manip... |
| CVE-2021-30325 | MEDIUM | 6.7 | 0.1% | Feb 11, 2022 | Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Au... |
| CVE-2021-30324 | MEDIUM | 6.7 | 0.1% | Feb 11, 2022 | Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to re... |
| CVE-2021-44970 | MEDIUM | 5.4 | 0.5% | Feb 10, 2022 | MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php. |
| CVE-2021-44969 | MEDIUM | 4.8 | 0.5% | Feb 10, 2022 | Taocms v3.0.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Management Column component. |
| CVE-2021-42000 | MEDIUM | 6.5 | 0.5% | Feb 10, 2022 | When a password reset or password change flow with an authentication policy is configured and the adapter in the reset o... |
| CVE-2021-44850 | MEDIUM | 6.8 | 0.2% | Feb 10, 2022 | On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the RO... |
| CVE-2021-45357 | MEDIUM | 6.1 | 0.8% | Feb 10, 2022 | Cross Site Scripting (XSS) vulnerability exists in Piwigo 12.x via the pwg_activity function in include/functions.inc.ph... |
| CVE-2021-41445 | MEDIUM | 6.1 | 2.4% | Feb 10, 2022 | A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote un... |
| CVE-2021-3398 | MEDIUM | 5.8 | 0.9% | Feb 10, 2022 | Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component. |
| CVE-2021-37613 | MEDIUM | 6.5 | 0.4% | Feb 10, 2022 | Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service. |
| CVE-2021-31814 | MEDIUM | 6.1 | 0.2% | Feb 10, 2022 | In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sens... |
| CVE-2021-45901 | MEDIUM | 5.3 | 14.3% | Feb 10, 2022 | The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending ... |
| CVE-2021-40045 | MEDIUM | 5.5 | 0.1% | Feb 9, 2022 | There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful ... |
| CVE-2021-40015 | MEDIUM | 4.7 | 0.1% | Feb 9, 2022 | There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vul... |
| CVE-2021-39991 | MEDIUM | 5.5 | 0.2% | Feb 9, 2022 | There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitatio... |
| CVE-2021-39986 | MEDIUM | 5.5 | 0.2% | Feb 9, 2022 | There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitatio... |
| CVE-2021-39943 | MEDIUM | 4.3 | 0.9% | Feb 9, 2022 | An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 bef... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now