2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23555CRITICAL9.8The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node ...
CVE-2021-20001CRITICAL9.8It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 co...
CVE-2021-4046MEDIUM5.4The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vuln...
CVE-2021-4035MEDIUM4.8A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of ...
CVE-2021-44111MEDIUM4.4A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.
CVE-2021-39688MEDIUM5.5In TBD of TBD, there is a possible out of bounds read due to TBD. This could lead to local information disclosure with n...
CVE-2021-39687MEDIUM5.5In HandleTransactionIoEvent of actuator_driver.cc, there is a possible out of bounds read due to a heap buffer overflow....
CVE-2021-39677HIGH7.5In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Produc...
CVE-2021-39676HIGH7.8In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improp...
CVE-2021-39675CRITICAL9.8In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead t...
CVE-2021-39674HIGH7.8In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead t...
CVE-2021-39672HIGH7.8In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of...
CVE-2021-39671MEDIUM6.5In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This ...
CVE-2021-39669HIGH7.8In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circum...
CVE-2021-39668HIGH7.8In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead...
CVE-2021-39666MEDIUM5.5In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could le...
CVE-2021-39665MEDIUM6.5In checkSpsUpdated of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This coul...
CVE-2021-39664MEDIUM5.5In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This cou...
CVE-2021-39663HIGH7.8In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due ...
CVE-2021-39662HIGH7.8In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider co...
CVE-2021-39658CRITICAL9.8ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does ...
CVE-2021-39635CRITICAL9.1ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions...
CVE-2021-39631MEDIUM5.5In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wron...
CVE-2021-39619HIGH7.8In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings ...
CVE-2021-39616CRITICAL9.8Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now