2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0870 | HIGH | 8.1 | 7.0% | Oct 22, 2021 | In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to... |
| CVE-2021-0708 | HIGH | 7.8 | 0.1% | Oct 22, 2021 | In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deput... |
| CVE-2021-0705 | HIGH | 7.8 | 0.3% | Oct 22, 2021 | In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and kee... |
| CVE-2021-0652 | HIGH | 7.8 | 0.2% | Oct 22, 2021 | In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due t... |
| CVE-2021-0483 | HIGH | 7.8 | 0.1% | Oct 22, 2021 | In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to loc... |
| CVE-2021-38479 | HIGH | 7.5 | 0.8% | Oct 22, 2021 | Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory re... |
| CVE-2021-38475 | HIGH | 8.8 | 0.9% | Oct 22, 2021 | The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to ... |
| CVE-2021-38473 | HIGH | 8.8 | 0.9% | Oct 22, 2021 | The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack ... |
| CVE-2021-38469 | HIGH | 7.1 | 0.6% | Oct 22, 2021 | Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker c... |
| CVE-2021-38467 | HIGH | 8.1 | 0.7% | Oct 22, 2021 | A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then con... |
| CVE-2021-38463 | HIGH | 8.1 | 0.7% | Oct 22, 2021 | The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited mem... |
| CVE-2021-38461 | HIGH | 8.2 | 0.5% | Oct 22, 2021 | The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted... |
| CVE-2021-34362 | HIGH | 7.2 | 1.3% | Oct 22, 2021 | A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, ... |
| CVE-2021-41127 | HIGH | 7.1 | 0.7% | Oct 21, 2021 | Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a... |
| CVE-2021-39352 | HIGH | 7.2 | 56.6% | Oct 21, 2021 | The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found... |
| CVE-2021-39321 | HIGH | 8.8 | 2.0% | Oct 21, 2021 | Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_... |
| CVE-2021-22034 | HIGH | 7.5 | 1.0% | Oct 21, 2021 | Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability. |
| CVE-2021-42716 | HIGH | 7.1 | 1.4% | Oct 21, 2021 | An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when c... |
| CVE-2021-41160 | HIGH | 8.8 | 1.6% | Oct 21, 2021 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected ve... |
| CVE-2021-41159 | HIGH | 8.8 | 1.3% | Oct 21, 2021 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP cl... |
| CVE-2021-41146 | HIGH | 8.8 | 1.4% | Oct 21, 2021 | qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows... |
| CVE-2021-35227 | HIGH | 7.8 | 0.5% | Oct 21, 2021 | The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available. |
| CVE-2021-29873 | HIGH | 8.1 | 1.5% | Oct 21, 2021 | IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service... |
| CVE-2021-20120 | HIGH | 8.8 | 0.5% | Oct 21, 2021 | The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery... |
| CVE-2021-41790 | HIGH | 8.8 | 1.4% | Oct 21, 2021 | An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now