2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-0870HIGH8.1In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to...
CVE-2021-0708HIGH7.8In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deput...
CVE-2021-0705HIGH7.8In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and kee...
CVE-2021-0652HIGH7.8In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due t...
CVE-2021-0483HIGH7.8In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to loc...
CVE-2021-38479HIGH7.5Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory re...
CVE-2021-38475HIGH8.8The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to ...
CVE-2021-38473HIGH8.8The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack ...
CVE-2021-38469HIGH7.1Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker c...
CVE-2021-38467HIGH8.1A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then con...
CVE-2021-38463HIGH8.1The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited mem...
CVE-2021-38461HIGH8.2The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted...
CVE-2021-34362HIGH7.2A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, ...
CVE-2021-41127HIGH7.1Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a...
CVE-2021-39352HIGH7.2The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found...
CVE-2021-39321HIGH8.8Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_...
CVE-2021-22034HIGH7.5Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.
CVE-2021-42716HIGH7.1An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when c...
CVE-2021-41160HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected ve...
CVE-2021-41159HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP cl...
CVE-2021-41146HIGH8.8qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows...
CVE-2021-35227HIGH7.8The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.
CVE-2021-29873HIGH8.1IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service...
CVE-2021-20120HIGH8.8The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery...
CVE-2021-41790HIGH8.8An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now