2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0688 | HIGH | 7 | 0.2% | Oct 6, 2021 | In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead t... |
| CVE-2021-0685 | HIGH | 7.8 | 0.2% | Oct 6, 2021 | In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to u... |
| CVE-2021-0684 | HIGH | 7.8 | 0.1% | Oct 6, 2021 | In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This... |
| CVE-2021-0683 | HIGH | 7.8 | 0.2% | Oct 6, 2021 | In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused d... |
| CVE-2021-0636 | HIGH | 7.8 | 0.3% | Oct 6, 2021 | When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video c... |
| CVE-2021-0635 | HIGH | 7.8 | 0.3% | Oct 6, 2021 | When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video c... |
| CVE-2021-0598 | HIGH | 7.3 | 0.1% | Oct 6, 2021 | In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacki... |
| CVE-2021-0595 | HIGH | 7.8 | 0.2% | Oct 6, 2021 | In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profi... |
| CVE-2021-28702 | HIGH | 7.6 | 0.4% | Oct 6, 2021 | PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Region... |
| CVE-2021-31988 | HIGH | 8.8 | 0.9% | Oct 5, 2021 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the ... |
| CVE-2021-31987 | HIGH | 7.5 | 0.9% | Oct 5, 2021 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass b... |
| CVE-2021-41124 | HIGH | 7.5 | 1.1% | Oct 5, 2021 | Scrapy-splash is a library which provides Scrapy and JavaScript integration. In affected versions users who use [`HttpAu... |
| CVE-2021-41120 | HIGH | 7.5 | 1.5% | Oct 5, 2021 | sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment... |
| CVE-2021-3581 | HIGH | 8.8 | 0.3% | Oct 5, 2021 | Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Len... |
| CVE-2021-3510 | HIGH | 7.5 | 0.9% | Oct 5, 2021 | Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access ... |
| CVE-2021-41113 | HIGH | 8.8 | 0.6% | Oct 5, 2021 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ... |
| CVE-2021-39226 | HIGH | 7.3 | 99.9% | Oct 5, 2021 | Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are ... |
| CVE-2021-35497 | HIGH | 7.5 | 0.4% | Oct 5, 2021 | The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO Active... |
| CVE-2021-41286 | HIGH | 7.8 | 0.2% | Oct 5, 2021 | Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the appli... |
| CVE-2021-35491 | HIGH | 8.1 | 0.9% | Oct 5, 2021 | A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to... |
| CVE-2021-41554 | HIGH | 8.8 | 0.8% | Oct 5, 2021 | ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functio... |
| CVE-2021-39893 | HIGH | 7.5 | 1.1% | Oct 5, 2021 | A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without auth... |
| CVE-2021-39867 | HIGH | 8.1 | 0.9% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by ... |
| CVE-2021-35505 | HIGH | 7.2 | 2.7% | Oct 5, 2021 | Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary... |
| CVE-2021-35504 | HIGH | 7.2 | 3.1% | Oct 5, 2021 | Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now