2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-39664MEDIUM5.5In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This cou...
CVE-2021-39631MEDIUM5.5In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wron...
CVE-2021-0524MEDIUM5.5In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages ...
CVE-2021-45387MEDIUM5.5tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.
CVE-2021-45386MEDIUM5.5tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c
CVE-2021-45385MEDIUM6.5A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information i...
CVE-2021-45402MEDIUM5.5The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bound...
CVE-2021-46355MEDIUM5.4OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manip...
CVE-2021-30325MEDIUM6.7Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Au...
CVE-2021-30324MEDIUM6.7Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to re...
CVE-2021-44970MEDIUM5.4MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.
CVE-2021-44969MEDIUM4.8Taocms v3.0.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Management Column component.
CVE-2021-42000MEDIUM6.5When a password reset or password change flow with an authentication policy is configured and the adapter in the reset o...
CVE-2021-44850MEDIUM6.8On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the RO...
CVE-2021-45357MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Piwigo 12.x via the pwg_activity function in include/functions.inc.ph...
CVE-2021-41445MEDIUM6.1A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote un...
CVE-2021-3398MEDIUM5.8Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component.
CVE-2021-37613MEDIUM6.5Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.
CVE-2021-31814MEDIUM6.1In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sens...
CVE-2021-45901MEDIUM5.3The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending ...
CVE-2021-40045MEDIUM5.5There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful ...
CVE-2021-40015MEDIUM4.7There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vul...
CVE-2021-39991MEDIUM5.5There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitatio...
CVE-2021-39986MEDIUM5.5There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitatio...
CVE-2021-39943MEDIUM4.3An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 bef...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now