2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-0688HIGH7In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead t...
CVE-2021-0685HIGH7.8In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to u...
CVE-2021-0684HIGH7.8In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This...
CVE-2021-0683HIGH7.8In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused d...
CVE-2021-0636HIGH7.8When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video c...
CVE-2021-0635HIGH7.8When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video c...
CVE-2021-0598HIGH7.3In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacki...
CVE-2021-0595HIGH7.8In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profi...
CVE-2021-28702HIGH7.6PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Region...
CVE-2021-31988HIGH8.8A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the ...
CVE-2021-31987HIGH7.5A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass b...
CVE-2021-41124HIGH7.5Scrapy-splash is a library which provides Scrapy and JavaScript integration. In affected versions users who use [`HttpAu...
CVE-2021-41120HIGH7.5sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment...
CVE-2021-3581HIGH8.8Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Len...
CVE-2021-3510HIGH7.5Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access ...
CVE-2021-41113HIGH8.8TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ...
CVE-2021-39226HIGH7.3Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are ...
CVE-2021-35497HIGH7.5The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO Active...
CVE-2021-41286HIGH7.8Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the appli...
CVE-2021-35491HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to...
CVE-2021-41554HIGH8.8ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functio...
CVE-2021-39893HIGH7.5A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without auth...
CVE-2021-39867HIGH8.1In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by ...
CVE-2021-35505HIGH7.2Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary...
CVE-2021-35504HIGH7.2Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now